{"id":"GHSA-58r4-h6v8-jcvm","summary":"Regression in JWT Signature Validation","details":"### Overview\nVersions after and including `2.3.0` are improperly validating the JWT token signature when using the `JWTValidator.verify` method.  Improper validation of the JWT token signature when not using the default Authorization Code Flow can allow an attacker to bypass authentication and authorization.\n\n### Am I affected?\nYou are affected by this vulnerability if all of the following conditions apply:\n\n- You are using `omniauth-auth0`.\n- You are using `JWTValidator.verify` method directly OR you are not authenticating using the SDK’s default Authorization Code Flow.\n\n### How to fix that?\nUpgrade to version `2.4.1`.\n\n### Will this update impact my users?\nThe fix provided in this version will not affect your users.","aliases":["CVE-2020-15240"],"modified":"2026-07-08T05:59:47.963127968Z","published":"2020-11-03T02:31:38Z","database_specific":{"cwe_ids":["CWE-287","CWE-347"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-10-27T19:10:29Z","nvd_published_at":"2020-10-21T18:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/auth0/omniauth-auth0/security/advisories/GHSA-58r4-h6v8-jcvm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15240"},{"type":"WEB","url":"https://github.com/auth0/omniauth-auth0/commit/fd3a14f4ccdfbc515d1121d6378ff88bf55a7a7a"},{"type":"PACKAGE","url":"https://github.com/auth0/omniauth-auth0"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth-auth0/CVE-2020-15240.yml"},{"type":"WEB","url":"https://rubygems.org/gems/omniauth-auth0"}],"affected":[{"package":{"name":"omniauth-auth0","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-auth0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.4.1"}]}],"versions":["2.3.0","2.3.1","2.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-58r4-h6v8-jcvm/GHSA-58r4-h6v8-jcvm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}