ZeroHour

CVE-2024-29901

CVSS 3.1
8.1 high
EPSS
<1%p49
Published
()
Modified
Description

The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2.

Vendors
workos
Products
authkit-nextjs
Weakness
CWE-294
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.