Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. FusionAuth/
  3. FusionAuth Security

FusionAuth Security

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 5/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 4 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Customer identity and access management platform with authentication features

by FusionAuth · fusionauth.io · source ↗

Known CVEs (4)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2022-45921 ↗HIGH 7.52022

    FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by…

  • CVE-2021-27736 ↗MEDIUM 6.52021

    FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.

  • CVE-2020-12676 ↗CRITICAL 9.12020

    FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".

  • CVE-2020-7799 ↗HIGH 7.22020

    An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Settings -> Email Templates) or themes (Home -> Settings -> Themes), can execute c…

Materials

2

Datasheets

  • Fusionauth Vs Auth0 ↗

Case studies

  • Dealcloser Case Study ↗

Other CIAM products

see all →
  • Auth0 Platform · Okta
  • Clerk · Clerk
  • Descope CIAM Platform · Descope
  • Frontegg CIAM · Frontegg
  • Hanko · Hanko
  • Journey Trusted Identity Platform · Journey
  • LoginRadius Customer Identity · LoginRadius
  • Okta Auth0 · Auth0