Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wmg-9cvh-qw25

Опубликовано: 05 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 0.4

Описание

@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled

Impact

Refresh tokens are logged to the console when the disabled by default debug flag, is enabled.

Patches

Patched in https://github.com/workos/authkit-nextjs/releases/tag/v0.13.2

Пакеты

Наименование

@workos-inc/authkit-nextjs

npm
Затронутые версииВерсия исправления

< 0.13.2

0.13.2

EPSS

Процентиль: 34%
0.00134
Низкий

0.4 Low

CVSS4

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
nvd
больше 1 года назад

The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 34%
0.00134
Низкий

0.4 Low

CVSS4

Дефекты

CWE-532