Security Advisory

CVE-2025-46345

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-05-01 17:20:24
Last updated 2025-05-02 17:39:32
Assigner GitHub_M
State PUBLISHED

Description

Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper authorization. This issue has been patched in versions 2.6.7, 2.7.0, and 3.0.0. It is recommended to upgrade to version 3.0.0 or greater.