CVE-2020-15125
Estado: ModificadaAlta (7.7)—
In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0's management API
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Puntuación base: 7.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.54%
- Percentil entre todas las CVEs puntuadas: 74
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-209
- CWE-209
Referencias
- https://github.com/auth0/node-auth0/pull/507
- https://github.com/auth0/node-auth0/pull/507/commits/62ca61b3348ec8e74d7d00358661af1a8bc98a3c
- https://github.com/auth0/node-auth0/security/advisories/GHSA-5jpf-pj32-xx53
- https://github.com/auth0/node-auth0/tree/v2.27.1
- https://github.com/auth0/node-auth0/pull/507
- https://github.com/auth0/node-auth0/pull/507/commits/62ca61b3348ec8e74d7d00358661af1a8bc98a3c
- https://github.com/auth0/node-auth0/security/advisories/GHSA-5jpf-pj32-xx53
- https://github.com/auth0/node-auth0/tree/v2.27.1
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-15125",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.7,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 3.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.7,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "auth0",
"product": "node-auth0",
"versions": [
{
"status": "affected",
"version": "< 2.27.1"
}
]
}
]
}
],
"published": "2020-07-29T17:15:13.577",
"references": [
{
"url": "https://github.com/auth0/node-auth0/pull/507",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/node-auth0/pull/507/commits/62ca61b3348ec8e74d7d00358661af1a8bc98a3c",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/node-auth0/security/advisories/GHSA-5jpf-pj32-xx53",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/node-auth0/tree/v2.27.1",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/auth0/node-auth0/pull/507",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/auth0/node-auth0/pull/507/commits/62ca61b3348ec8e74d7d00358661af1a8bc98a3c",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/auth0/node-auth0/security/advisories/GHSA-5jpf-pj32-xx53",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/auth0/node-auth0/tree/v2.27.1",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-209"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-209"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0's management API"
},
{
"lang": "es",
"value": "En auth0 (paquete npm) versiones anteriores a 2.27.1, se usa una DenyList de claves específicas que deben ser saneadas desde el objeto de petición contenido en el objeto de error. La clave para el encabezado Authorization no se sanea y, en determinados casos , el valor del encabezado Authorization puede ser registrado exponiendo un token de portador. Esta afectado por esta vulnerabilidad si está usando el paquete auth0 npm y está utilizando una aplicación Máquina a Máquina autorizada para usar la API de administración de Auth0"
}
],
"lastModified": "2026-06-17T02:56:05.993",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:auth0:auth0.js:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DA78EE6-5A3F-472F-AC51-2306140A3ED5",
"versionEndExcluding": "2.27.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}