User Interface (UI) Misrepresentation of Critical Information Affecting next package, versions >=10.0.0 <12.1.0
Threat Intelligence
EPSS
0.18% (57th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-NEXT-2405694
- published 18 Feb 2022
- disclosed 18 Feb 2022
- credit Unknown
Introduced: 18 Feb 2022
CVE-2022-23646 Open this link in a new tabHow to fix?
Upgrade next
to version 12.1.0 or higher.
Overview
next is a react framework.
Affected versions of this package are vulnerable to User Interface (UI) Misrepresentation of Critical Information due to improper CSP (content security policy).
Note: In order to be affected ALL of the following must be true:
Next.js between version 10.0.0 and 12.0.10.
The
next.config.js
file hasimages.domains
array assigned.The image host assigned in
images.domains
allows user-provided SVG
Not affected: The next.config.js
file has images.loader
assigned to something other than "default".
References
CVSS Scores
version 3.1