Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28079 | Brute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDK |
Github GHSA |
GHSA-g98g-r7gf-2r25 | Brute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDK |
Thu, 22 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Forgeable Encrypted Session Cookie in Apps Using Auth0-PHP SDK | Brute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDK |
Fri, 16 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 May 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior to version 8.14.0, session cookies of applications using the Auth0-PHP SDK configured with CookieStore have authentication tags that can be brute forced, which may result in unauthorized access. Certain pre-conditions are required to be vulnerable to this issue: Applications using the Auth0-PHP SDK, or the Auth0/symfony, Auth0/laravel-auth0, and Auth0/wordpress SDKs that rely on the Auth0-PHP SDK; and session storage configured with CookieStore. Upgrade Auth0/Auth0-PHP to v8.14.0 to receive a patch. As an additional precautionary measure, rotating cookie encryption keys is recommended. Note that once updated, any previous session cookies will be rejected. | |
| Title | Forgeable Encrypted Session Cookie in Apps Using Auth0-PHP SDK | |
| Weaknesses | CWE-287 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-22T20:03:34.201Z
Reserved: 2025-05-05T16:53:10.372Z
Link: CVE-2025-47275
Updated: 2025-05-16T13:37:42.164Z
Status : Deferred
Published: 2025-05-15T22:15:18.667
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-47275
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA