Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Auth0 auth0-aspnet和auth0-aspnet-owin 安全漏洞
Vulnerability Description
Auth0 auth0-aspnet和auth0-aspnet-owin都是美国Auth0公司的产品。Auth0 auth0-aspnet是一款使用ASP.NET配置AuthO的工具。auth0-aspnet-owin是一款Owin/Katana身份验证处理程序。 Auth0 auth0-aspnet和auth0-aspnet-owin中存在安全漏洞,该漏洞源于受影响的包没有使用或检测OAuth 2.0和OpenID Connect协议的‘state’参数。攻击者可利用该漏洞执行未授权的操作。
CVSS Information
N/A
Vulnerability Type
N/A