Description
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-7307
Related Vulnerabilities
CVE-2018-1000865 Vulnerability in maven package org.kohsuke:groovy-sandbox
CVE-2023-27602 Vulnerability in maven package org.apache.linkis:linkis-storage-script-dev-server
CVE-2015-5348 Vulnerability in maven package org.apache.camel:camel-http
CVE-2010-4172 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2012-0838 Vulnerability in maven package org.apache.struts.xwork:xwork-core