Description
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-7307
Related Vulnerabilities
CVE-2011-4905 Vulnerability in maven package org.apache.activemq:activemq-core
CVE-2015-5255 Vulnerability in maven package org.apache.flex.blazeds:flex-messaging-core
CVE-2020-17150 Vulnerability in npm package typescript-tslint-plugin
CVE-2018-6341 Vulnerability in maven package org.webjars.npm:react-dom