Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Default redirect callback vulnerable to open redirects
Vulnerability Description
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any reason, you can add a configuration to your callbacks option. If you already have a `redirect` callback, make sure that you match the incoming `url` origin against the `baseUrl`.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
Vulnerability Type
使用欺骗进行的认证绕过
Vulnerability Title
next-auth 输入验证错误漏洞
Vulnerability Description
next-auth是Next.js应用程序的完整开源身份验证解决方案。 next-auth 3.29.2 之前存在安全漏洞,目前暂无该漏洞信息,请随时关注CNNVD或厂商公告。
CVSS Information
N/A
Vulnerability Type
N/A