4.24.12
7 years ago
1 days ago
Known vulnerabilities in the next-auth package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
next-auth is an Authentication for Next.js Affected versions of this package are vulnerable to Improper Neutralization in the email validation component. An attacker can intercept sensitive authentication emails by submitting a specially crafted email address that manipulates the parsing logic, causing messages to be sent to an unintended mailbox. How to fix Improper Neutralization? Upgrade | <4.24.12>=5.0.0-beta.0 <5.0.0-beta.30 |
next-auth is an Authentication for Next.js Affected versions of this package are vulnerable to Improper Authorization by obtaining an issued JWT from an interrupted OAuth sign-in flow. An attacker can manually override the Notes:
How to fix Improper Authorization? Upgrade | <4.24.5 |