NextAuth.js
cpe:2.3:a:nextauth.js:next-auth:*:*:*:*:node.js:*:*
- < 4.10.2
- < 3.29.9
A vulnerability allowing information disclosure has been identified in NextAuth.js versions prior to 4.10.2 and 3.29.9. This issue arises during OAuth error handling, where an attacker with log access can retrieve sensitive information, such as an identity provider's secret, from the logs. This leaked information could be exploited to impersonate the client and request additional permissions. The vulnerability has been addressed in versions 4.10.2 and 3.29.9 by changing the log level for provider information and adding a warning about the debug option in production.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, allowing an attacker to impersonate a client and request additional permissions.
Users can upgrade to NextAuth.js version 4.10.2 or 3.29.9. If an upgrade is not possible, the 'logger' configuration option can be used to sanitize logs by redacting sensitive provider information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.