Description
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
Remediation
References
http://www.securityfocus.com/bid/103695
https://auth0.com/docs/security/bulletins/cve-2018-6873
Related Vulnerabilities
CVE-2023-26487 Vulnerability in npm package vega
CVE-2018-20822 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2021-32620 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2017-16038 Vulnerability in npm package f2e-server
CVE-2020-7610 Vulnerability in maven package org.webjars.npm:bson