Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Adamjmcgrath

#42209of 53,624
6.4Total CVSS
Vulnerabilities · 1
PT-2021-23952
6.4
2021-12-16
Auth0 · Auth0 Next.Js Sdk · CVE-2021-43812
Name of the Vulnerable Software and Affected Versions: Auth0 Next.js SDK versions prior to 1.6.2 Description: The issue is related to the Auth0 Next.js SDK, a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain `returnTo` parameter values from the login url, exposing the application to an open redirect vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue. Recommendations: Upgrade to version 1.6.2 or later, as this version contains the necessary fix for the issue. This update will not affect users.