GHSA-mmhr-3jr7-qj2p
Dashboard / Vulnerabilities / GHSA-mmhr-3jr7-qj2p
Summary: Auth0-ASPNET and Auth0-ASPNET-Owin vulnerable to Cross-Site Request Forgery
Details: An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-15121, https://auth0.com/docs/security/bulletins/cve-2018-15121, https://github.com/auth0/auth0-aspnet-owin, https://www.nuget.org/packages/Auth0-ASPNET-Owin
Affected packages
Package
Name: Auth0-ASPNET-Owin
Purl: pkg:nuget/Auth0-ASPNET-Owin
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
