Junglewise Threat Intelligence

CVE-2022-29172: Auth0 Lock cross-site scripting via additional signup fields

CVE-2022-29172 · Severity: low · CVSS 3.1 · Published 2022-05-24

Technologies: auth0-lock (npm), Auth0 Lock. Vendors: npm, Auth0.

Executive brief

Auth0 Lock is a widely-used authentication UI widget used by applications to handle user sign-up and login. When the "additional signup fields" feature is enabled, malicious users can inject unvalidated HTML code that gets stored in user metadata and rendered in verification emails, potentially allowing attackers to send phishing emails or trick users into clicking malicious links that appear to come from legitimate sources.

Technical details

This is a cross-site scripting (CWE-79) vulnerability in the additional signup fields feature of Auth0 Lock. The vulnerability exists because user input provided in additional signup fields is not properly sanitized before being stored in the service's user_metadata payload. When verification emails are generated, this unsanitized metadata (specifically the name property) is rendered directly into the email template without HTML escaping. An attacker can craft a malicious signup request injecting HTML/JavaScript into these fields, which is then delivered to victims via email, potentially enabling phishing attacks or credential theft. The fix, released in version 11.33.0, strips HTML tags from user input in additional signup fields on the signup tab.

Affected products

  • Auth0 Lock 11.32.2 and earlier

Timeline

  • 2022-05-05: disclosed
  • 2022-05-24: advisory
  • 2022-05-24: patched: Version 11.33.0 released

References

Related threats