wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
297 stars 59 forks source link

Authentication bypass in Auth0 #309

Closed LabanSkollerSentor closed 2 months ago

LabanSkollerSentor commented 3 months ago

I hope this vulnerability fits even though I never had the chance to prove it in their production environment and even though Auth0/Okta never commented the vulnerability.

Feel free to generate some image, fill in missing information etcetera.

korniko98 commented 2 months ago

hi @LabanSkollerSentor, this is currently out of scope of this database, since it isn't directly related to a cloud service provider. however, if at any point in this future we expand this project to include vulnerabilities affecting other service providers as well, then we will be sure to include this submission.