Description
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-7307
Related Vulnerabilities
CVE-2017-12620 Vulnerability in maven package org.apache.opennlp:opennlp-tools
CVE-2020-8913 Vulnerability in maven package com.google.android.play:core
CVE-2022-36919 Vulnerability in maven package org.jenkins-ci.plugins:coverity
CVE-2014-3623 Vulnerability in maven package org.apache.ws.security:wss4j