Intel

AIKIDO-2024-10353

@kinde-oss/kinde-auth-nextjs is vulnerable to Improper Certificate Validation

Improper Certificate Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

95

Critical Risk

This Affects:

js@kinde-oss/kinde-auth-nextjs
1.8.3 - 2.3.11
Fixed in 2.3.12

TL;DR

Affected versions of the package allow login bypass due to a failure in validating the certificate during the authentication process. As a result, an attacker could exploit this vulnerability to bypass authentication and gain unauthorized access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@kinde-oss/kinde-auth-nextjs is vulnerable to Improper Certificate Validation in versions 1.8.3 - 2.3.11.

How to fix this

Upgrade the @kinde-oss/kinde-auth-nextjs library to the patch version.