Vulnerability Description
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Auth0 | Angular-Jwt | < 0.1.10 |
Related Weaknesses (CWE)
References
- https://auth0.com/docs/security/bulletins/cve-2018-11537PatchVendor Advisory
- https://auth0.com/docs/security/bulletins/cve-2018-11537PatchVendor Advisory
FAQ
What is CVE-2018-11537?
CVE-2018-11537 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypas...
How severe is CVE-2018-11537?
CVE-2018-11537 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11537?
Check the references section above for vendor advisories and patch information. Affected products include: Auth0 Angular-Jwt.