Description
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-7307
Related Vulnerabilities
CVE-2022-36127 Vulnerability in npm package skywalking-backend-js
CVE-2023-40167 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2016-4003 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-6429 Vulnerability in npm package electron
CVE-2017-4963 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server