auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized and user input or data from URL parameters is incorporated into the `flashMessage` or the library's `languageDictionary` feature is utilized and user input or data from URL parameters is incorporated into the `languageDictionary`. The vulnerability is patched in version 11.30.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-1348 auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized and user input or data from URL parameters is incorporated into the `flashMessage` or the library's `languageDictionary` feature is utilized and user input or data from URL parameters is incorporated into the `languageDictionary`. The vulnerability is patched in version 11.30.1.
Github GHSA Github GHSA GHSA-jr3j-whm4-9wwm Reflected XSS when using flashMessages or languageDictionary
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-03T23:25:31.021Z

Reserved: 2021-05-12T00:00:00

Link: CVE-2021-32641

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-04T21:15:07.573

Modified: 2024-11-21T06:07:26.347

Link: CVE-2021-32641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses