OktaOKTA-0D6JW07
JWT Invalid Signature Validation in Auth0 Account Linking Extensions CVE-2025-46345 - Apr...
UnratedCVE-2025-46345 · Published Apr 30, 2025
Auth0 Account Linking Extensions versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. Upgrade to the latest version 3.0.0 or greater.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 222025 | Okta On-Premises Provisioning (OPP) Password Reset Information Disclosure CVE-2025-7371... | Unrated | No fix yet |
| Jun 32025 | Deserialization of Untrusted Data in Auth0-PHP SDK CVE-2025-48951 - Jun 3, 2025 | Unrated | No fix yet |
| Jun 32025 | CDN Caching of Session Cookies in NextJS-Auth0 SDK CVE-2025-48947 - Jun 3, 2025 | Unrated | No fix yet |
| May 152025 | Brute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDK CVE-2025-47275... | Unrated | No fix yet |
| May 62025 | SAML Signature Wrapping Vulnerability Leading to User Impersonation in Passport-WS-Fed... | Unrated | No fix yet |
| May 62025 | SAML Attribute Smuggling Vulnerability Allowing User Impersonation in Passport-WS-Fed... | Unrated | No fix yet |