PT-2024-28631 · Next.Js · Next.Js
0Dd
+2
·
Published
2024-07-10
·
Updated
2024-07-11
·
CVE-2024-39693
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Next.js versions prior to 13.5
Description
A Denial of Service (DoS) condition was identified in Next.js, which can trigger a crash and affect the availability of the server upon exploitation. This issue can affect all Next.js deployments on the affected versions.
Recommendations
For versions prior to 13.5, upgrade to Next.js version 13.5 or later to resolve the issue. As a temporary workaround, consider implementing measures to prevent the exploitation of the Denial of Service condition, such as restricting access to the server or implementing rate limiting. However, the most effective solution is to upgrade to a safe version.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Next.Js