Description
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-7307
Related Vulnerabilities
CVE-2017-15703 Vulnerability in maven package org.apache.nifi:nifi-authorizer
CVE-2023-37914 Vulnerability in maven package org.xwiki.platform:xwiki-platform-invitation-ui
CVE-2023-0100 Vulnerability in maven package org.eclipse.birt:org.eclipse.birt.report.viewer
CVE-2020-5397 Vulnerability in maven package org.springframework:spring-webflux
CVE-2017-1000394 Vulnerability in maven package org.jenkins-ci.main:jenkins-core