Versions before and including 2.27.0 use a block list of specific keys that should be sanitized from the request object contained in the error object. When a request to Auth0 management API fails, the key for Authorization header is not sanitized and the Authorization header value can be logged exposing a bearer token.
You are affected by this vulnerability if all of the following conditions apply:
auth0 npm packageUpgrade to version 2.27.1
The fix provided in patch will not affect your users.
http://github.com/osdiab
{
"cwe_ids": [
"CWE-209"
],
"github_reviewed_at": "2020-07-29T16:25:59Z",
"github_reviewed": true,
"severity": "HIGH",
"nvd_published_at": null
}