Intel

AIKIDO-2024-10317

@kinde-oss/kinde-auth-nextjs is vulnerable to Storage of Sensitive Information in a Cookie

Storage of Sensitive Information in a Cookie Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 3, 2024

40

Medium Risk

This Affects:

js@kinde-oss/kinde-auth-nextjs
1.8.19 - 1.10.1
Fixed in 1.10.2
2.0.0 - 2.3.8
Fixed in 2.3.9
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to storage of sensitive information in a cookie. The API access token is stored in the cookie under the name kinde_api_access_token, potentially exposing it to unauthorized access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@kinde-oss/kinde-auth-nextjs is vulnerable to Storage of Sensitive Information in a Cookie in versions 1.8.19 - 1.10.1 and 2.0.0 - 2.3.8.

How to fix this

Upgrade the @kinde-oss/kinde-auth-nextjs library to the patch version.