Auth.js是Auth.js组织的一款提供身份验证功能的开发框架。 Auth.js 0.41.3之前版本、next-auth 4.24.15之前版本和5.0.0-beta.4及之后且5.0.0-beta.32之前版本存在安全漏洞,该漏洞源于Auth.js将OAuth/OIDC反CSRF校验状态、nonce和PKCE验证器存储在未绑定创建提供商的全局cookie中,且回调时未验证cookie与回调提供商的身份,导致一个提供商的校验值可被另一个提供商接受,在多提供商应用中攻击者可诱骗受害者发起合法同源流程并
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| @auth | core | < 0.41.3 |
affected |
| nextauthjs | next-auth | < 4.24.15 |
affected |
>= 5.0.0-beta.4, < 5.0.0-beta.32 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextauthjs | next-auth | < 4.24.15 | - |
|
| @auth | core | < 0.41.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet