PT-2020-14307 · Vercel · Next.Js

Timneutkens

·

Published

2020-10-08

·

Updated

2020-12-03

·

CVE-2020-15242

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Next.js versions 9.5.0 through 9.5.3
Description The issue allows for an Open Redirect, where specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur to an external site. This redirect does not directly harm users, although it can allow for phishing attacks by redirecting to an attacker's domain from a trusted domain.
Recommendations For Next.js versions 9.5.0 through 9.5.3, upgrade to version 9.5.4 to resolve the issue. As a temporary workaround, consider restricting access to specially encoded paths to minimize the risk of exploitation.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15242
GHSA-X56P-C8CG-Q435

Affected Products

Next.Js