CVE-2025-46345

Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper authorization. This issue has been patched in versions 2.6.7, 2.7.0, and 3.0.0. It is recommended to upgrade to version 3.0.0 or greater.
CVSS

No CVSS.

Configurations

No configuration.

History

02 May 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) Auth0 Account Link Extension facilita la vinculación de cuentas. Las versiones 2.3.4 a 2.6.6 no verifican la firma del JWT proporcionado. Esto permite al usuario proporcionar un token falsificado y acceder a la información del usuario sin la debida autorización. Este problema se ha corregido en las versiones 2.6.7, 2.7.0 y 3.0.0. Se recomienda actualizar a la versión 3.0.0 o superior.

01 May 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 18:15

Updated : 2025-05-02 13:52


NVD link : CVE-2025-46345

Mitre link : CVE-2025-46345

CVE.ORG link : CVE-2025-46345


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing