CVE-2023-48309
- EPSS 0.3%
- Veröffentlicht 20.11.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:31:27
NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization are affected by a vulnerability. A bad actor could create an empty/mock user, by getting hold of a Nex...
CVE-2023-27490
- EPSS 0.23%
- Veröffentlicht 09.03.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:53:00
NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A bad actor who can read traffic...
CVE-2022-39263
- EPSS 0.26%
- Veröffentlicht 28.09.2022 21:15:14
- Zuletzt bearbeitet 21.11.2024 07:17:54
`@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js. Applications that use `next-auth` Email Provider and `@next-auth/upstash-redis-adapter` before v3.0.2 are affected by this vul...
CVE-2022-35924
- EPSS 0.42%
- Veröffentlicht 02.08.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:11:58
NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker could forge a request that sent a...
CVE-2022-31127
- EPSS 0.59%
- Veröffentlicht 06.07.2022 18:15:19
- Zuletzt bearbeitet 21.11.2024 07:03:57
NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin endpoint](https://next-auth.js.org/getting-started/rest-api#post-apiauthsigninprovider) that contai...
CVE-2022-31093
- EPSS 0.86%
- Veröffentlicht 27.06.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:03:52
NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker can send a request to an app using NextAuth.js with an invalid `callbackUrl` query parameter, which internally is converted to a ...
CVE-2022-29214
- EPSS 0.24%
- Veröffentlicht 21.05.2022 00:15:11
- Zuletzt bearbeitet 21.11.2024 06:58:44
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1 provider. Versions 3.29.3 and 4.3....
CVE-2022-24858
- EPSS 0.32%
- Veröffentlicht 19.04.2022 23:15:13
- Zuletzt bearbeitet 21.11.2024 06:51:15
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any reason, you can add a configur...
CVE-2021-21310
- EPSS 0.37%
- Veröffentlicht 11.02.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:59
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database adapter in conjunction with the Email...