Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-37699

Опубликовано: 12 авг. 2021
Источник: nvd
CVSS3: 6.9
CVSS3: 6.1
CVSS2: 5.8
EPSS Низкий

Описание

Next.js is an open source website development framework to be used with the React library. In affected versions specially encoded paths could be used when pages/_error.js was statically generated allowing an open redirect to occur to an external site. In general, this redirect does not directly harm users although can allow for phishing attacks by redirecting to an attacker's domain from a trusted domain. We recommend everyone to upgrade regardless of whether you can reproduce the issue or not. The issue has been patched in release 11.1.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*
Версия от 10.0.5 (включая) до 10.2.0 (включая)
cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*
Версия от 11.0.0 (включая) до 11.0.1 (включая)

EPSS

Процентиль: 62%
0.0043
Низкий

6.9 Medium

CVSS3

6.1 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-601
CWE-601

Связанные уязвимости

CVSS3: 6.9
github
почти 4 года назад

Open Redirect in Next.js

EPSS

Процентиль: 62%
0.0043
Низкий

6.9 Medium

CVSS3

6.1 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-601
CWE-601