Description
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-7307
Related Vulnerabilities
CVE-2017-12648 Vulnerability in maven package com.liferay:com.liferay.frontend.taglib
CVE-2015-5344 Vulnerability in maven package org.apache.camel:camel-xstream
CVE-2023-50773 Vulnerability in maven package com.zintow:dingding-json-pusher
CVE-2023-50767 Vulnerability in maven package org.sonatype.nexus.ci:nexus-jenkins-plugin
CVE-2022-34815 Vulnerability in maven package org.jenkins-ci.plugins:rrod