state
parameter in and Connect (OIDC) protocols that allows an attacker to inject their authorization code into victim’s session.
auth0-aspnet
or auth0-aspnet-owin
, you are affected by this vulnerability.
Microsoft.Owin.Security.OpenIdConnect
package, which is not vulnerable.
If your application is not currently making use of OWIN, please refer to Microsoft’s OWIN documentation to enable it in your application.