Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Vulnerability Description
NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In middleware, Route Handlers, React Server Components, and other auth() entry points, a non-OK session response is parsed into a truthy error object instead of null, so checks such as !!auth and if (req.auth) evaluate to true for unauthenticated requests. A provider missing both the issuer and authorization endpoint triggers InvalidEndpoints, and an unset AUTH_SECRET or another server configuration error can produce the same behavior. There is no impact while configuration is valid, but after a deployment becomes misconfigured, routes protected only by session existence silently grant access to every visitor. This issue is fixed in next-auth 5.0.0-beta.32.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
Auth.js 授权问题漏洞
Vulnerability Description
Auth.js是Auth.js组织的一款身份验证开发框架。 Auth.js 5.0.0-beta.0至5.0.0-beta.32之前版本存在安全漏洞,该漏洞源于仅检查auth()包装器返回的auth对象存在性进行访问控制,当Auth.js服务器配置错误时,非OK会话响应被解析为真值错误对象,导致未认证请求通过身份验证检查,可能允许所有访客访问仅受会话存在性保护的路由。
CVSS Information
N/A
Vulnerability Type
N/A