Open redirect in @auth0/nextjs-auth0
Moderate severity
GitHub Reviewed
Published
Dec 16, 2021
in
auth0/nextjs-auth0
•
Updated Feb 1, 2023
Description
Reviewed
Dec 16, 2021
Published to the GitHub Advisory Database
Dec 16, 2021
Published by the National Vulnerability Database
Dec 16, 2021
Last updated
Feb 1, 2023
Overview
Versions
<=1.6.1do not filter out certainreturnToparameter values from the login url, which expose the application to an open redirect vulnerability.Am I affected?
You are affected by this vulnerability if you are using
@auth0/nextjs-auth0version<=1.6.1.How to fix that?
Upgrade to version
>=1.6.2Will this update impact my users?
The fix provided in the patch will not affect your users.
References