Description
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-11537
Related Vulnerabilities
CVE-2013-2160 Vulnerability in maven package org.codehaus.woodstox:woodstox-core-asl
CVE-2023-24446 Vulnerability in maven package org.jenkins-ci.plugins:openid
CVE-2023-46652 Vulnerability in maven package org.jenkins-ci.plugins:lambdatest-automation
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk15to18
CVE-2016-10707 Vulnerability in maven package org.webjars.bower:jquery