Description
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-7307
Related Vulnerabilities
CVE-2006-1547 Vulnerability in maven package struts:struts
CVE-2016-10366 Vulnerability in npm package kibana
CVE-2020-2110 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2018-1999040 Vulnerability in maven package org.csanchez.jenkins.plugins:kubernetes
CVE-2018-6341 Vulnerability in maven package org.webjars.bowergithub.vuejs:vue