CVE-2017-17068: Information Exposure
(updated )
A cross-origin vulnerability has been discovered in auth0. This vulnerability allows an attacker to acquire authenticated user tokens and invoke services on a user’s behalf if the target site or application uses a popup callback page with auth0.popup.callback().
References
Detect and mitigate CVE-2017-17068 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →