Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wr66-vrwm-5g5x

Опубликовано: 28 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Denial of Service Vulnerability in next.js

Impact

Vulnerable code could allow a bad actor to trigger a denial of service attack for anyone running a Next.js app at version >= 12.0.0, and using i18n functionality.

  • Affected: All of the following must be true to be affected by this CVE
    • Next.js versions above v12.0.0
    • Using next start or a custom server
    • Using the built-in i18n support
  • Not affected:
    • Deployments on Vercel (vercel.com) are not affected along with similar environments where invalid requests are filtered before reaching Next.js.

Patches

A patch has been released, next@12.0.9, that mitigates this issue. We recommend all affected users upgrade as soon as possible.

Workarounds

We recommend upgrading whether you can reproduce or not although you can ensure /${locale}/_next/ is blocked from reaching the Next.js instance until you upgrade.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

next

npm
Затронутые версииВерсия исправления

>= 12.0.0, < 12.0.9

12.0.9

EPSS

Процентиль: 80%
0.01472
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-400

Связанные уязвимости

CVSS3: 5.9
nvd
больше 3 лет назад

Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a bad actor to trigger a denial of service attack for anyone using i18n functionality. In order to be affected by this CVE, one must use next start or a custom server and the built-in i18n support. Deployments on Vercel, along with similar environments where invalid requests are filtered before reaching Next.js, are not affected. A patch has been released, `next@12.0.9`, that mitigates this issue. As a workaround, one may ensure `/${locale}/_next/` is blocked from reaching the Next.js instance until it becomes feasible to upgrade.

EPSS

Процентиль: 80%
0.01472
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-400