SCA: security update for auth0 (GHSA-5jpf-pj32-xx53)

high Tenable Cloud Security Plugin ID 410897

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from
the request object contained in the error object is used. The key for Authorization header is not
sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You
are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to
Machine application authorized to use Auth0's management API (CVE-2020-15125)

See Also

https://github.com/advisories/GHSA-5jpf-pj32-xx53

Plugin Details

Severity: High

ID: 410897

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.3

Percentile: 50.87

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2020-15125

CVSS v3

Risk Factor: High

Base Score: 7.7

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/29/2020

Vulnerability Publication Date: 7/29/2020

Reference Information

CVE: CVE-2020-15125

cwe: CWE-209