Description
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-11537
Related Vulnerabilities
CVE-2023-40185 Vulnerability in npm package shescape
CVE-2020-5263 Vulnerability in npm package auth0-js
CVE-2022-41940 Vulnerability in npm package engine.io
CVE-2023-35152 Vulnerability in maven package org.xwiki.platform:xwiki-platform-like-ui
CVE-2019-25155 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify