@auth0/nextjs-auth0/.../nextjs-auth0@0.14.0 vulnerabilities

Next.js SDK for signing in with Auth0

  • latest version

    3.5.0

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @auth0/nextjs-auth0 package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Information Exposure

    @auth0/nextjs-auth0 is a Next.js SDK for signing in with Auth0

    Affected versions of this package are vulnerable to Information Exposure as certain returnTo parameter values aren't filtered from the login URL, which exposes the application to an open redirect vulnerability.

    How to fix Information Exposure?

    Upgrade @auth0/nextjs-auth0 to version 1.6.2 or higher.

    <1.6.2
    • M
    Cross-site Scripting (XSS)

    @auth0/nextjs-auth0 is a Next.js SDK for signing in with Auth0

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the error query parameter.

    How to fix Cross-site Scripting (XSS)?

    Upgrade @auth0/nextjs-auth0 to version 1.4.1 or higher.

    <1.4.1