Authentication for Next.js
72%
Total Score
10
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2023-48309 next-auth is vulnerable to Improper Authorization in versions 0.0.0 - 4.24.5. | 0.0.0 - 4.24.5 | Medium |
CVE-2023-27490 next-auth is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.0 - 4.20.1. | 0.0.0 - 4.20.1 | High |
CVE-2022-31186 next-auth is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.0 - 3.29.9 and 4.0.0 - 4.10.2. | 0.0.0 - 3.29.94.0.0 - 4.10.2 | Low |
CVE-2022-35924 next-auth is vulnerable to Improper Input Validation in versions 4.0.0 - 4.10.3 and 0.0.0 - 3.29.10. | 0.0.0 - 3.29.104.0.0 - 4.10.3 | Critical |
CVE-2022-31127 next-auth is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.29.8 and 4.0.0 - 4.9.0. | 0.0.0 - 3.29.84.0.0 - 4.9.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
jose Version ^4.15.5 | — | — |
uuid Version ^8.3.2 | — | — |
oauth Version ^0.9.15 | — | — |
cookie Version ^0.7.0 | — | — |
preact Version ^10.6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant