Auth0

Nextjs-auth0

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 11.12.2025 00:21:27
  • Zuletzt bearbeitet 12.12.2025 15:18:13

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through 4.12.1 contain an input-validation flaw in the returnTo parameter, which could allow attackers to inject unintended OAuth query pa...

  • EPSS 0.04%
  • Veröffentlicht 10.12.2025 22:16:08
  • Zuletzt bearbeitet 12.12.2025 15:18:13

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache fo...

  • EPSS 0.08%
  • Veröffentlicht 04.06.2025 20:14:44
  • Zuletzt bearbeitet 05.06.2025 20:12:23

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers...

  • EPSS 0.09%
  • Veröffentlicht 29.04.2025 20:43:41
  • Zuletzt bearbeitet 02.05.2025 13:53:40

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE doe...

  • EPSS 0.2%
  • Veröffentlicht 16.12.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:50

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect vulnerabil...

  • EPSS 0.58%
  • Veröffentlicht 25.06.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:07:33

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and including `1.4.1` are vulnerable to reflected XSS. An attacker can execute arbitrary code by providing an XSS payload in the `error` ...