Записи nextauth.js
9 опубликованных записей вендора nextauth.js.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-290 Authentication Bypass by Spoofing2
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-754 Improper Check for Unusual or Exceptional Conditions1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2022-35924Эксплойта нет | Verification requests (magic link) sent to unwanted emailsnextauth.js · next-auth · CWE-20 | Критическая9,1 | — | 1,4 % | 2 авг. 2022 г. |
35Наблюдать | CVE-2023-27490Эксплойта нет | Missing proper state, nonce and PKCE checks for OAuth authentication in next-authnextauth.js · next-auth · CWE-352 | Высокая8,8 | — | 0,5 % | 9 мар. 2023 г. |
32Наблюдать | CVE-2022-39263Эксплойта нет | NextAuth.js Upstash Adapter missing token verificationnextauth.js · next-auth · CWE-287 | Высокая8,1 | — | 0,7 % | 28 сент. 2022 г. |
31Наблюдать | CVE-2022-31093Эксплойта нет | Improper Handling of `callbackUrl` parameter in next-authnextauth.js · next-auth · CWE-754 | Высокая7,5 | — | 1,7 % | 27 июн. 2022 г. |
24Наблюдать | CVE-2021-21310Эксплойта нет | Token verification bug in next-authnextauth.js · next-auth · CWE-290 | Средняя5,9 | — | 1,7 % | 11 февр. 2021 г. |
24Наблюдать | CVE-2022-31127Эксплойта нет | Improper handling of email input in next-authnextauth.js · next-auth · CWE-79 | Средняя6,1 | — | 1,1 % | 6 июл. 2022 г. |
24Наблюдать | CVE-2022-24858Эксплойта нет | Default redirect callback vulnerable to open redirectsnextauth.js · next-auth · CWE-290 | Средняя6,1 | — | 0,8 % | 19 апр. 2022 г. |
24Наблюдать | CVE-2022-29214Эксплойта нет | URL Redirection to Untrusted Site ('Open Redirect') in next-authnextauth.js · next-auth · CWE-601 | Средняя6,1 | — | 0,7 % | 20 мая 2022 г. |
21Наблюдать | CVE-2023-48309Эксплойта нет | next-auth vulnerable to possible user mocking that bypasses basic authenticationnextauth.js · next-auth · CWE-285 | Средняя5,3 | — | 0,7 % | 20 нояб. 2023 г. |
- CVE-2022-3592436Наблюдать
Verification requests (magic link) sent to unwanted emails
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %nextauth.js · next-auth2 авг. 2022 г.
- CVE-2023-2749035Наблюдать
Missing proper state, nonce and PKCE checks for OAuth authentication in next-auth
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nextauth.js · next-auth9 мар. 2023 г.
- CVE-2022-3926332Наблюдать
NextAuth.js Upstash Adapter missing token verification
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %nextauth.js · next-auth28 сент. 2022 г.
- CVE-2022-3109331Наблюдать
Improper Handling of `callbackUrl` parameter in next-auth
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %nextauth.js · next-auth27 июн. 2022 г.
- CVE-2021-2131024Наблюдать
Token verification bug in next-auth
СредняяCVSS 5,9Эксплойта нетEPSS 2 %nextauth.js · next-auth11 февр. 2021 г.
- CVE-2022-3112724Наблюдать
Improper handling of email input in next-auth
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nextauth.js · next-auth6 июл. 2022 г.
- CVE-2022-2485824Наблюдать
Default redirect callback vulnerable to open redirects
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nextauth.js · next-auth19 апр. 2022 г.
- CVE-2022-2921424Наблюдать
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
СредняяCVSS 6,1Эксплойта нетEPSS 1 %nextauth.js · next-auth20 мая 2022 г.
- CVE-2023-4830921Наблюдать
next-auth vulnerable to possible user mocking that bypasses basic authentication
СредняяCVSS 5,3Эксплойта нетEPSS 1 %nextauth.js · next-auth20 нояб. 2023 г.