












Under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided.
You are affected if you meet each of the following preconditions:
Applications built using Auth0.js version between 8.11.0 and 9.32.0
The application’s access control relies on rules defined in Auth0 Actions.
Upgrade auth0/auth0.js to version 10.0.0 or greater.
Okta would like to thank Quan Le (@aleister1102) for their discovery and responsible disclosure.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。