We found results for “”
CVE-2021-32641
Good to know:
Date: June 4, 2021
auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including "11.30.0" are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's "flashMessage" feature is utilized and user input or data from URL parameters is incorporated into the "flashMessage" or the library's "languageDictionary" feature is utilized and user input or data from URL parameters is incorporated into the "languageDictionary". The vulnerability is patched in version 11.30.1.
Language: JS
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | MEDIUM |
| Authentication (AU): | NONE |
| Confidentiality (C): | NONE |
| Integrity (I): | PARTIAL |
| Availability (A): | NONE |
| Additional information: |
Vulnerabilities
Projects
Contact Us


