Impact
Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From version 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens supplied in the token URL query parameter as well as from the Authorization header for protected HTTP routes. Because tokens can be logged in server logs, browser history, or referrer data, an attacker who captures a token could replay it against protected API endpoints, gaining unauthorized access. The weakness is identified as CWE-598 and is resolved in version 5.9.0.
Affected Systems
Auth0 Symfony, a Symfony SDK for Auth0 Authentication and Management APIs, is impacted. Versions from 5.0.0-BETA0 through 5.8.x (inclusive) allow the query-string token behavior. Version 5.9.0 and later address the issue, so those are not affected.
Risk and Exploitability
Based on the description, it is inferred that the most likely attack vector involves sending an HTTP request with a bearer token in the query string to a protected route. The CVSS score of 6.5 indicates a medium impact, and the EPSS score of < 1% signals an extremely low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The token can be captured from logs or history for replay, allowing an attacker to hijack sessions or perform actions on the holder's behalf. The vulnerability applies only to affected versions and is mitigated by upgrading to 5.9.0 or later.
OpenCVE Enrichment
Github GHSA