Overview
Versions before and including11.25.1
are using dangerouslySetInnerHTML
to display an informational message when used with a or Enterprise connection.
- For a Passwordless connection, the value of the input (email or phone number) is displayed back to the user while waiting for verification code input.
- For an Enterprise connection, the value of the input ( Domain) from the Enterprise connection setup screen () is displayed back to the user when the Lock widget opens.
Am I affected?
You are affected by this vulnerability if all of the following conditions apply:- You are using
auth0-lock
- You are using Passwordless or Enterprise connection mode
How to fix that?
Upgrade to version11.26.3
.