Описание
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.
Ссылки
- Release NotesVendor Advisory
- PatchRelease Notes
- PatchVendor Advisory
- Release NotesVendor Advisory
- PatchRelease Notes
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.7.0 (включая) до 4.29.3 (исключая)
cpe:2.3:a:clerk:javascript:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 49%
0.00264
Низкий
9 Critical
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 9
github
около 2 лет назад
@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)
EPSS
Процентиль: 49%
0.00264
Низкий
9 Critical
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-284