Kinde Auth SDK for NextJS
90%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10389 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @kinde-oss/kinde-auth-nextjs is vulnerable to Improper Certificate Validation in versions 1.8.1 - 2.3.11. | 1.8.1 - 2.3.11 | Medium |
AIKIDO-2024-10353 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @kinde-oss/kinde-auth-nextjs is vulnerable to Improper Certificate Validation in versions 1.8.3 - 2.3.11. | 1.8.3 - 2.3.11 | Critical |
AIKIDO-2024-10317 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @kinde-oss/kinde-auth-nextjs is vulnerable to Storage of Sensitive Information in a Cookie in versions 1.8.19 - 1.10.1 and 2.0.0 - 2.3.8. | 1.8.19 - 1.10.12.0.0 - 2.3.8 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
destr Version ^2.0.5 | — | — |
cookie Version ^1.0.2 | — | — |
uncrypto Version ^0.1.3 | — | — |
crypto-js Version ^4.2.0 | — | — |
@kinde/jwt-decoder Version ^0.2.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant