Nextauth.Js

Next-auth

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 20.11.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 08:31:27

NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization are affected by a vulnerability. A bad actor could create an empty/mock user, by getting hold of a Nex...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 09.03.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 07:53:00

NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A bad actor who can read traffic...

  • EPSS 0.26%
  • Veröffentlicht 28.09.2022 21:15:14
  • Zuletzt bearbeitet 21.11.2024 07:17:54

`@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js. Applications that use `next-auth` Email Provider and `@next-auth/upstash-redis-adapter` before v3.0.2 are affected by this vul...

  • EPSS 0.42%
  • Veröffentlicht 02.08.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:11:58

NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker could forge a request that sent a...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 06.07.2022 18:15:19
  • Zuletzt bearbeitet 21.11.2024 07:03:57

NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin endpoint](https://next-auth.js.org/getting-started/rest-api#post-apiauthsigninprovider) that contai...

  • EPSS 0.86%
  • Veröffentlicht 27.06.2022 22:15:09
  • Zuletzt bearbeitet 21.11.2024 07:03:52

NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker can send a request to an app using NextAuth.js with an invalid `callbackUrl` query parameter, which internally is converted to a ...

  • EPSS 0.24%
  • Veröffentlicht 21.05.2022 00:15:11
  • Zuletzt bearbeitet 21.11.2024 06:58:44

NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1 provider. Versions 3.29.3 and 4.3....

  • EPSS 0.32%
  • Veröffentlicht 19.04.2022 23:15:13
  • Zuletzt bearbeitet 21.11.2024 06:51:15

next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any reason, you can add a configur...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 11.02.2021 22:15:12
  • Zuletzt bearbeitet 21.11.2024 05:47:59

NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database adapter in conjunction with the Email...