OSV 1.4.0 · github-reviewed · 修改于 2021-12-17 02:42
发布时间
2021-12-17 02:52
GitHub 审查时间
2021-12-17 02:42
NVD 发布时间
2021-12-17 03:15
源文件
advisories/github-reviewed/2021/12/GHSA-2mqv-4j3r-vjvp/GHSA-2mqv-4j3r-vjvp.json
Versions <=1.6.1 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect vulnerability.
You are affected by this vulnerability if you are using @auth0/nextjs-auth0 version <=1.6.1.
Upgrade to version >=1.6.2
The fix provided in the patch will not affect your users.