漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
next-intl has an open redirect vulnerability
Vulnerability Description
next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host (e.g. scheme-relative `//` or control characters stripped by the URL parser), so the middleware could redirect the browser off-site while the user still started from a trusted app URL. The problem has been patchedin `next-intl@4.9.1`.
CVSS Information
N/A
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Vulnerability Title
next-intl 安全漏洞
Vulnerability Description
next-intl是Jan Amann个人开发者的一个Next.js解决方案。 next-intl 4.9.1之前版本存在安全漏洞,该漏洞源于中间件路径处理不当,可能导致重定向到不受信任的主机。
CVSS Information
N/A
Vulnerability Type
N/A