7.5

CVE-2023-46298

Exploit
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vercel ≫ Next.Js SwPlatform node.js Version < 13.4.20
Vercel ≫ Next.Js Version 13.4.20 Update canary0 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary1 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary10 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary11 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary12 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary2 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary3 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary4 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary5 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary6 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary7 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary8 SwPlatform node.js
Vercel ≫ Next.Js Version 13.4.20 Update canary9 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.28% 0.663
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/vercel/next.js/compare/v13.4.20-canary.12...v13.4.20-canary.13
Product
https://github.com/vercel/next.js/issues/45301
Third Party Advisory
Exploit
Issue Tracking
https://github.com/vercel/next.js/pull/54732
Patch
Issue Tracking