The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "9.3"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:auth0:auth0.js:*:*:*:*:*:*:*:*"
}