The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade next to version 16.3.8 or higher.
next is a react framework.
Affected versions of this package are vulnerable to Use of Cache Containing Sensitive Information via cross-request deduplication in the use-cache-wrapper.ts cache function, where draft mode state is not accounted for when sharing cached fills across concurrent requests. A draft mode request can join a pending public cache fill and receive published content instead of draft content, or conversely, a fill executed under draft mode containing unpublished content can be registered and served to non-draft requests.
Note: This is only exploitable when the 'use cache' directive is in use and concurrent requests occur, one of which has draft mode enabled.