Vulnerabilidades em nextauthjs
10 resultadosAnálise Vexday
NextAuth.js apresenta 10 vulnerabilidades conhecidas na base, com 1 classificada como crítica, mas nenhuma sob exploração ativa até o momento. A fraqueza dominante (CWE-290) aponta para problemas de autenticação e verificação de identidade, risco estrutural que demanda atenção mesmo sem ataques em curso. O perfil de risco é contido pela ausência de publicações recentes, indicando que a superfície de ataque não se expandiu nos últimos 90 dias.
CVE-2021-21310MEDIUMToken verification bug in next-authEPSS 1.7%CVE-2022-31093HIGHImproper Handling of `callbackUrl` parameter in next-authEPSS 1.6%CVE-2022-35924CRITICALVerification requests (magic link) sent to unwanted emailsEPSS 1.4%CVE-2022-31127HIGHImproper handling of email input in next-authEPSS 1.1%CVE-2022-24858MEDIUMDefault redirect callback vulnerable to open redirectsEPSS 0.8%CVE-2023-48309MEDIUMnext-auth vulnerable to possible user mocking that bypasses basic authenticationEPSS 0.7%CVE-2022-29214MEDIUMURL Redirection to Untrusted Site ('Open Redirect') in next-authEPSS 0.6%CVE-2022-39263MEDIUMNextAuth.js Upstash Adapter missing token verificationEPSS 0.6%CVE-2023-27490HIGHMissing proper state, nonce and PKCE checks for OAuth authentication in next-authEPSS 0.5%CVE-2022-31186LOWLeakage of excessive information into log in next-authEPSS 0.3%