PT-2024-28631 · Next.Js · Next.Js

0Dd

+2

·

Published

2024-07-10

·

Updated

2024-07-11

·

CVE-2024-39693

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Next.js versions prior to 13.5
Description A Denial of Service (DoS) condition was identified in Next.js, which can trigger a crash and affect the availability of the server upon exploitation. This issue can affect all Next.js deployments on the affected versions.
Recommendations For versions prior to 13.5, upgrade to Next.js version 13.5 or later to resolve the issue. As a temporary workaround, consider implementing measures to prevent the exploitation of the Denial of Service condition, such as restricting access to the server or implementing rate limiting. However, the most effective solution is to upgrade to a safe version.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-39693
GHSA-FQ54-2J52-JC42

Affected Products

Next.Js