{"id":"GHSA-c9cg-q8r2-xvjq","summary":"Improper Authentication in Auth0.AuthenticationApi","details":"Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.","aliases":["CVE-2019-16929"],"modified":"2023-11-08T04:01:22.386634Z","published":"2019-10-24T20:56:12Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2019-10-24T20:55:50Z","nvd_published_at":"2019-10-08T13:15:00Z","cwe_ids":["CWE-287"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16929"},{"type":"WEB","url":"https://auth0.com/docs/security/bulletins/cve-2019-16929"}],"affected":[{"package":{"name":"Auth0.AuthenticationApi","ecosystem":"NuGet","purl":"pkg:nuget/Auth0.AuthenticationApi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.8.0"},{"fixed":"6.5.4"}]}],"versions":["5.10.0","5.11.0","5.8.0","5.9.0","6.0.0","6.1.0","6.2.0","6.3.0","6.4.0","6.5.0","6.5.1","6.5.2","6.5.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-c9cg-q8r2-xvjq/GHSA-c9cg-q8r2-xvjq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}