Description
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
Remediation
References
http://www.securityfocus.com/bid/103695
https://auth0.com/docs/security/bulletins/cve-2018-6873
Related Vulnerabilities
CVE-2017-12882 Vulnerability in maven package org.springframework.batch:spring-batch-admin
CVE-2019-14517 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2020-7752 Vulnerability in npm package systeminformation
CVE-2021-21368 Vulnerability in maven package org.webjars.npm:msgpack5
CVE-2019-10354 Vulnerability in maven package org.jenkins-ci.main:jenkins-core