Description
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-7307
Related Vulnerabilities
CVE-2011-1475 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2018-10899 Vulnerability in maven package org.jolokia:jolokia-core
CVE-2015-0254 Vulnerability in maven package org.apache.taglibs:taglibs-standard
CVE-2012-5887 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-35926 Vulnerability in npm package @backstage/plugin-scaffolder-backend