PT-2020-14307 · Vercel · Next.Js
Timneutkens
·
Published
2020-10-08
·
Updated
2020-12-03
·
CVE-2020-15242
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Next.js versions 9.5.0 through 9.5.3
Description
The issue allows for an Open Redirect, where specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur to an external site. This redirect does not directly harm users, although it can allow for phishing attacks by redirecting to an attacker's domain from a trusted domain.
Recommendations
For Next.js versions 9.5.0 through 9.5.3, upgrade to version 9.5.4 to resolve the issue.
As a temporary workaround, consider restricting access to specially encoded paths to minimize the risk of exploitation.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Next.Js