{"id":"CVE-2020-15240","aliases":["GHSA-58r4-h6v8-jcvm"],"url":"https://o3.security/vulnerability/CVE-2020-15240","summary":"Regression in JWT Signature Validation","details":"omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Improper validation of the JWT token signature can allow an attacker to bypass authentication and authorization. You are affected by this vulnerability if all of the following conditions apply: 1. You are using `omniauth-auth0`. 2. You are using `JWTValidator.verify` method directly OR you are not authenticating using the SDK’s default Authorization Code Flow. The issue is patched in version 2.4.1.","published":"2020-10-21T18:15:12.813Z","modified":"2026-07-09T06:34:42.489654Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"RubyGems","name":"omniauth-auth0","fixedVersion":"2.4.1"}],"fix":{"url":"https://github.com/auth0/omniauth-auth0/commit/fd3a14f4ccdfbc515d1121d6378ff88bf55a7a7a","label":"auth0/omniauth-auth0@fd3a14f"},"references":[{"type":"ADVISORY","url":"https://github.com/auth0/omniauth-auth0/security/advisories/GHSA-58r4-h6v8-jcvm"},{"type":"ADVISORY","url":"https://rubygems.org/gems/omniauth-auth0"},{"type":"FIX","url":"https://github.com/auth0/omniauth-auth0/commit/fd3a14f4ccdfbc515d1121d6378ff88bf55a7a7a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T06:34:42.489654Z"}}