« Volver al listado

CVE-2025-68129

Estado: AnalizadaAlta (7.5)—

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects are affected if they use Auth0-PHP SDK versions between v8.0.0 and v8.17.0, or applications using the following SDKs that rely on the Auth0-PHP SDK versions between v8.0.0 and v8.17.0: Auth0/symfony versions between 5.0.0 and 5.5.0, Auth0/laravel-auth0 versions between 7.0.0 and 7.19.0, and/or Auth0/wordpress plugin versions between 5.0.0-BETA0 and 5.4.0. Auth0/Auth0-PHP version 8.18.0 contains a patch for the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Red sin privilegios, validación impropia de tokens que permite usar ID tokens como access tokens (CWE-863: acceso impropio). Impacto: acceso con identidad falsa (T1078) y exposición de credenciales en tokens (T1552.007).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-68129",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-68129",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-18T14:53:59.445866Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "auth0",
          "product": "auth0-PHP",
          "versions": [
            {
              "status": "affected",
              "version": ">= 8.0.0, < 8.18.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-12-17T22:16:01.713",
  "references": [
    {
      "url": "https://github.com/auth0/auth0-PHP/commit/7fe700053aee609718460c123f00f53c511f0f7f",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/auth0-PHP/releases/tag/8.18.0",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/auth0-PHP/security/advisories/GHSA-j2vm-wrq3-f7gf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/laravel-auth0/commit/a1c3344dc0e5a36e8f56c8cfc535728d3d7558f3",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/laravel-auth0/releases/tag/7.20.0",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/laravel-auth0/security/advisories/GHSA-7hh9-gp72-wh7h",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/symfony/commit/0103d6f8dcef6996653fad1f823d1c167f472479",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/symfony/releases/tag/5.6.0",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/symfony/security/advisories/GHSA-f3r2-88mq-9v4g",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/wordpress/commit/b207c6f7fd06507b90c4e6bcc18a857ef9e018de",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/wordpress/releases/tag/5.5.0",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/auth0/wordpress/security/advisories/GHSA-vvg7-8rmq-92g7",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects are affected if they use Auth0-PHP SDK versions between v8.0.0 and v8.17.0, or applications using the following SDKs that rely on the Auth0-PHP SDK versions between v8.0.0 and v8.17.0: Auth0/symfony versions between 5.0.0 and 5.5.0, Auth0/laravel-auth0 versions between 7.0.0 and 7.19.0, and/or Auth0/wordpress plugin versions between 5.0.0-BETA0 and 5.4.0. Auth0/Auth0-PHP version 8.18.0 contains a patch for the issue."
    },
    {
      "lang": "es",
      "value": "Auth0-PHP es un SDK de PHP para las API de autenticación y gestión de Auth0. En aplicaciones construidas con el SDK de Auth0-PHP, la validación de audiencia en los tokens de acceso se realiza de forma incorrecta. Sin una validación adecuada, las aplicaciones afectadas pueden aceptar tokens de ID como tokens de acceso. Los proyectos se ven afectados si utilizan versiones del SDK de Auth0-PHP entre v8.0.0 y v8.17.0, o aplicaciones que utilizan los siguientes SDK que dependen de las versiones del SDK de Auth0-PHP entre v8.0.0 y v8.17.0: versiones de Auth0/symfony entre 5.0.0 y 5.5.0, versiones de Auth0/laravel-auth0 entre 7.0.0 y 7.19.0, y/o versiones del plugin de WordPress de Auth0 entre 5.0.0-BETA0 y 5.4.0. La versión 8.18.0 de Auth0/Auth0-PHP contiene un parche para el problema."
    }
  ],
  "lastModified": "2026-09-30T23:10:00.237",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:auth0:auth0-php:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12378349-3A0C-4E82-9568-C0B4B775F1F4",
              "versionEndExcluding": "8.18.0",
              "versionStartIncluding": "8.0.0"
            },
            {
              "criteria": "cpe:2.3:a:auth0:laravel-auth0:*:*:*:*:*:laravel:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01BEB1D0-CD7D-4223-ADC3-7DB8DB852867",
              "versionEndExcluding": "7.20.0",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:auth0:symfony:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1093AE14-FD36-4E4D-983E-48D4CCE77D49",
              "versionEndExcluding": "5.6.0",
              "versionStartIncluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:auth0:wp-auth0:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C6C5FAD-40FC-4715-B4C1-419EC9AC51FB",
              "versionEndExcluding": "5.5.0",
              "versionStartIncluding": "5.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}