Auth0 Next.js SDK
cpe:2.3:a:auth0:nextjs-auth0:*:*:*:*:node.js:*:*
- <= 1.6.1
An open redirect vulnerability has been identified in the Auth0 Next.js SDK, specifically in versions through 1.6.1. The issue arises because the SDK does not properly validate certain returnTo parameter values in the login URL, allowing for potential redirection to malicious sites. This vulnerability could be exploited by manipulating the returnTo parameter to redirect users to an external URL, potentially leading to phishing attacks or other malicious activities.
Exploitation of this vulnerability allows for open redirect, where users can be redirected to an external site of the attacker's choice.
To reproduce this vulnerability, use the Auth0 Next.js SDK version 1.6.1 or earlier. Initiate the login process and include a returnTo parameter that points to an external URL. The application will redirect to the specified URL, demonstrating the open redirect vulnerability.
Users should upgrade to version 1.6.2 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.