Vulnerabilities (CVE)

Filtered by vendor Auth0
Filtered by product Express Openid Connect
Angry Yack Logo
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24794 1 Auth0 1 Express Openid Connect 2024-11-21 5.8 MEDIUM 7.5 HIGH
Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or through the default `authRequired` option, are vulnerable to an Open Redirect when the middleware is applied to a catch all route. If all routes under `example.com` are protected with the `requiresAuth` middleware, a visit to `http://example.com//google.com` will be redirected to `google.com` after login because the original ...

Show More

CVE-2021-41246 1 Auth0 1 Express Openid Connect 2024-11-21 6.8 MEDIUM 4.6 MEDIUM
Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session fixation vulnerabilities. Versions `2.5.2` contains a patch for this issue.