{"api_version":"v1","generated_at":"2026-10-07T05:30:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-auth0-lock-672d71447f65","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/lock","name":"lock","next_cursor":null,"observations":[{"affected":"< 11.33.0","affected_versions_present":true,"cve_id":"CVE-2022-29172","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-29172","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:30:53.070Z","patch_url":"https://github.com/auth0/lock/commit/79ae557d331274b114848150f19832ae341771b1","primary_source":"","published":"2022-05-05T22:50:09.000Z"},{"affected":"<= 11.30.0","affected_versions_present":true,"cve_id":"CVE-2021-32641","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-32641","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T23:25:31.021Z","patch_url":"https://github.com/auth0/lock/commit/d139cf01c8234b07caf265e051f39d3eab08f7ed","primary_source":"","published":"2021-06-04T21:10:11.000Z"},{"affected":"<= 11.25.1","affected_versions_present":true,"cve_id":"CVE-2020-15119","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-15119","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T13:08:21.963Z","patch_url":"","primary_source":"","published":"2020-08-19T21:20:11.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"auth0"}}
