CVE-2022-29172 is a medium-severity vulnerability affecting Auth0 Lock versions prior to 11.33.0 when the "additional signup fields" feature is enabled. An unauthenticated attacker can inject malicious HTML into these fields, which is then stored in user metadata and rendered in verification emails, potentially leading to crafted malicious links. The CVSS score is 6.1, indicating a network-based attack with low complexity, requiring user interaction, and resulting in low confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.33.0CPE matchmatch criteria | cpe:2.3:a:auth0:lock:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.