Description
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-7307
Related Vulnerabilities
CVE-2022-45143 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-41934 Vulnerability in maven package org.xwiki.platform:xwiki-platform-menu-ui
CVE-2021-41084 Vulnerability in maven package org.http4s:http4s-server_3
CVE-2015-2156 Vulnerability in maven package io.netty:netty
CVE-2020-15096 Vulnerability in maven package org.webjars.npm:electron