Description
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2714 | Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN. |
Github GHSA |
GHSA-c59h-r6p8-q9wc | Next.js missing cache-control header may lead to CDN caching empty reply |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-12T17:50:34.208Z
Reserved: 2023-10-22T00:00:00.000Z
Link: CVE-2023-46298
Updated: 2024-08-02T20:45:40.898Z
Status : Modified
Published: 2023-10-22T03:15:07.630
Modified: 2024-11-21T08:28:15.220
Link: CVE-2023-46298
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA