next is vulnerable to Information Disclosure
63
Medium Risk
With Cache Components enabled, a 'use cache' function in next that calls another 'use cache' function reading a root param can omit that param from its own cache key. The outer entry is written once, by whichever request arrives first, and then reused for every root param value. Content produced for one value can be sent for another, including from prerendered pages and downstream caches. The fix includes the root param in the outer cache key.
You are affected if you are using a version that falls within the vulnerable range and you enable Cache Components with nested 'use cache' functions that read a root param.
next is vulnerable to Information Disclosure in versions 16.3.0 - 16.3.7.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.