Auth0

Ad/ldap Connector

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 08.09.2026 20:18:09
  • Zuletzt bearbeitet 10.09.2026 15:17:50

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lea...

Medienbericht
  • EPSS 0.22%
  • Veröffentlicht 08.09.2026 20:17:40
  • Zuletzt bearbeitet 10.09.2026 15:17:49

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify direct...

  • EPSS 0.12%
  • Veröffentlicht 08.09.2026 20:17:06
  • Zuletzt bearbeitet 10.09.2026 15:17:49

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel'...

  • EPSS 0.97%
  • Veröffentlicht 06.11.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:05:12

ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or confidential data loss. CSRF exploits may occur if the user visits a malicious page containing CSRF pa...