@kinde-oss/kinde-auth-nextjs is vulnerable to Improper Certificate Validation
95
Critical Risk
Affected versions of the package allow login bypass due to a failure in validating the certificate during the authentication process. As a result, an attacker could exploit this vulnerability to bypass authentication and gain unauthorized access.
You are affected if you are using a version that falls within the vulnerable range.
@kinde-oss/kinde-auth-nextjs is vulnerable to Improper Certificate Validation in versions 1.8.3 - 2.3.11.
Upgrade the @kinde-oss/kinde-auth-nextjs library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant