nextauth.js kayıtları
nextauth.js üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-290 Authentication Bypass by Spoofing2
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-754 Improper Check for Unusual or Exceptional Conditions1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2022-35924İstismar yok | Verification requests (magic link) sent to unwanted emailsnextauth.js · next-auth · CWE-20 | Kritik9,1 | — | %1,4 | 2 Ağu 2022 |
35İzleyin | CVE-2023-27490İstismar yok | Missing proper state, nonce and PKCE checks for OAuth authentication in next-authnextauth.js · next-auth · CWE-352 | Yüksek8,8 | — | %0,5 | 9 Mar 2023 |
32İzleyin | CVE-2022-39263İstismar yok | NextAuth.js Upstash Adapter missing token verificationnextauth.js · next-auth · CWE-287 | Yüksek8,1 | — | %0,7 | 28 Eyl 2022 |
31İzleyin | CVE-2022-31093İstismar yok | Improper Handling of `callbackUrl` parameter in next-authnextauth.js · next-auth · CWE-754 | Yüksek7,5 | — | %1,7 | 27 Haz 2022 |
24İzleyin | CVE-2021-21310İstismar yok | Token verification bug in next-authnextauth.js · next-auth · CWE-290 | Orta5,9 | — | %1,7 | 11 Şub 2021 |
24İzleyin | CVE-2022-31127İstismar yok | Improper handling of email input in next-authnextauth.js · next-auth · CWE-79 | Orta6,1 | — | %1,1 | 6 Tem 2022 |
24İzleyin | CVE-2022-24858İstismar yok | Default redirect callback vulnerable to open redirectsnextauth.js · next-auth · CWE-290 | Orta6,1 | — | %0,8 | 19 Nis 2022 |
24İzleyin | CVE-2022-29214İstismar yok | URL Redirection to Untrusted Site ('Open Redirect') in next-authnextauth.js · next-auth · CWE-601 | Orta6,1 | — | %0,7 | 20 May 2022 |
21İzleyin | CVE-2023-48309İstismar yok | next-auth vulnerable to possible user mocking that bypasses basic authenticationnextauth.js · next-auth · CWE-285 | Orta5,3 | — | %0,7 | 20 Kas 2023 |
- CVE-2022-3592436İzleyin
Verification requests (magic link) sent to unwanted emails
KritikCVSS 9,1İstismar yokEPSS %1nextauth.js · next-auth2 Ağu 2022
- CVE-2023-2749035İzleyin
Missing proper state, nonce and PKCE checks for OAuth authentication in next-auth
YüksekCVSS 8,8İstismar yokEPSS %1nextauth.js · next-auth9 Mar 2023
- CVE-2022-3926332İzleyin
NextAuth.js Upstash Adapter missing token verification
YüksekCVSS 8,1İstismar yokEPSS %1nextauth.js · next-auth28 Eyl 2022
- CVE-2022-3109331İzleyin
Improper Handling of `callbackUrl` parameter in next-auth
YüksekCVSS 7,5İstismar yokEPSS %2nextauth.js · next-auth27 Haz 2022
- CVE-2021-2131024İzleyin
Token verification bug in next-auth
OrtaCVSS 5,9İstismar yokEPSS %2nextauth.js · next-auth11 Şub 2021
- CVE-2022-3112724İzleyin
Improper handling of email input in next-auth
OrtaCVSS 6,1İstismar yokEPSS %1nextauth.js · next-auth6 Tem 2022
- CVE-2022-2485824İzleyin
Default redirect callback vulnerable to open redirects
OrtaCVSS 6,1İstismar yokEPSS %1nextauth.js · next-auth19 Nis 2022
- CVE-2022-2921424İzleyin
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
OrtaCVSS 6,1İstismar yokEPSS %1nextauth.js · next-auth20 May 2022
- CVE-2023-4830921İzleyin
next-auth vulnerable to possible user mocking that bypasses basic authentication
OrtaCVSS 5,3İstismar yokEPSS %1nextauth.js · next-auth20 Kas 2023