
We found results for “”
CVE-2025-46345
Good to know:

Date: May 1, 2025
Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper authorization. This issue has been patched in versions 2.6.7, 2.7.0, and 3.0.0. It is recommended to upgrade to version 3.0.0 or greater.
Severity Score
Related Resources (4)
Severity Score
Weakness Type (CWE)
Authentication Bypass by Spoofing
CWE-290Top Fix

Upgrade Version
Upgrade to version https://github.com/auth0-extensions/auth0-account-link-extension.git - v3.0.0
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |