📦

angular-jwt

Vendor: auth0

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 1.14% Exploit Prob.
Latest CVE CVE-2018-11537 Jun 19

Security Vulnerability Index

Page 1 / 1
6.5 CVSS

Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.

EPSS: 1.14%