Auth0是是一个身份验证代理,支持社会和企业身份提供者,包括Active Directory、LDAP、谷歌Apps和Salesforce。 Auth0 Next.js SDK 1.6.2之前版本存在输入验证错误漏洞,该漏洞源于程序不会从登录url中过滤掉某些returnTo参数值,这将使应用程序暴露在开放重定向漏洞中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| auth0 | nextjs-auth0 | < 1.6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet