icon

We found results for “

CVE-2024-29901

Good to know:

icon
icon

Date: March 29, 2024

The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2.

Language: TYPE_SCRIPT

Severity Score

Severity Score

Weakness Type (CWE)

Authentication Bypass by Capture-replay

CWE-294

Top Fix

icon

Upgrade Version

Upgrade to version @workos-inc/authkit-nextjs - 0.4.2

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us