PT-2021-21819 · Next.Js · Next.Js

Timneutkens

·

Published

2021-08-11

·

Updated

2021-08-20

·

CVE-2021-37699

CVSS v3.1

6.9

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Next.js versions prior to 11.1.0
Description The issue in Next.js allows an open redirect to occur to an external site when specially encoded paths are used with statically generated pages/ error.js. This redirect does not directly harm users but can allow for phishing attacks by redirecting to an attacker's domain from a trusted domain.
Recommendations For versions prior to 11.1.0, upgrade to the latest version of Next.js to improve the overall security of your application. As a temporary workaround, consider restricting access to the pages/ error.js file until the issue is resolved. Avoid using specially encoded paths in the pages/ error.js file to minimize the risk of exploitation.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37699
GHSA-VXF5-WXWP-M7G9

Affected Products

Next.Js