Junglewise Threat Intelligence

CVE-2021-32641: Auth0 Lock reflected XSS in flashMessages and languageDictionary

CVE-2021-32641 · Severity: low · CVSS 3.1 · Published 2021-06-04

Technologies: auth0-lock (npm), Auth0 Lock. Vendors: npm, Auth0.

Executive brief

Auth0 Lock is a universal login widget used by applications to handle user authentication. Versions up to 11.30.0 are vulnerable to reflected cross-site scripting (XSS) attacks when flashMessage or languageDictionary features incorporate unsanitized user input or URL parameters. An attacker can craft a malicious URL to inject arbitrary JavaScript code that executes in a user's browser, potentially allowing account takeover, credential theft, or session hijacking.

Technical details

The vulnerability is a reflected XSS (CWE-79) affecting the auth0-lock library up to version 11.30.0. The root cause is insufficient input validation and encoding in the flashMessage and languageDictionary features, which directly incorporate user-supplied data or URL parameters into the DOM without sanitization. Attack vector is network-based with no authentication required; an attacker sends a victim a crafted URL containing malicious JavaScript payload. Precondition: the application must use flashMessage or languageDictionary features and pass unsanitized user input or query parameters to these features. An attacker can execute arbitrary JavaScript in the victim's browser context. The vulnerability is patched in version 11.30.1, which uses DOMPurify to sanitize inputs.

Affected products

  • Auth0 Lock <=11.30.0

Timeline

  • 2021-06-04: disclosed
  • 2021-06-04: patched: Version 11.30.1 released with DOMPurify sanitization

References

Related threats