Open redirect in @auth0/nextjs-auth0
Moderate severity
GitHub Reviewed
Published
Dec 16, 2021
in
auth0/nextjs-auth0
•
Updated Feb 1, 2023
Description
Reviewed
Dec 16, 2021
Published to the GitHub Advisory Database
Dec 16, 2021
Published by the National Vulnerability Database
Dec 16, 2021
Last updated
Feb 1, 2023
Overview
Versions
<=1.6.1
do not filter out certainreturnTo
parameter values from the login url, which expose the application to an open redirect vulnerability.Am I affected?
You are affected by this vulnerability if you are using
@auth0/nextjs-auth0
version<=1.6.1
.How to fix that?
Upgrade to version
>=1.6.2
Will this update impact my users?
The fix provided in the patch will not affect your users.
References