Filtered by vendor Auth0 Subscriptions
Filtered by product Angular-jwt Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-11537 1 Auth0 1 Angular-jwt 2024-11-21 N/A
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.