PT-2024-34884 · Remix+1 · Remix+1

Marji-Workos

·

Published

2024-11-05

·

Updated

2024-11-06

·

CVE-2024-51753

CVSS v4.0

2.1

Low

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AuthKit library for Remix versions prior to 0.4.1
Description The issue concerns the logging of refresh tokens to the console when the debug flag is enabled. This flag is disabled by default. There are no known workarounds for this issue. All users are advised to upgrade to a patched version.
Recommendations For versions prior to 0.4.1, upgrade to version 0.4.1 to resolve the issue. As a temporary workaround, consider disabling the debug flag until the upgrade is applied.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-51753
GHSA-V2QH-F584-6HJ8

Affected Products

Authkit
Remix