GHSA-vm2p-f5j4-mj6g
MODERATECVE-2018-11537Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain allowlist filter via a crafted domain.
- Affected
- < 0.1.10
- Fixed in
- 0.1.10
- Weakness
- CWE-20
- Published
- 2022-05-14
- Source
- github