Description
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0398 | Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3. |
Github GHSA |
GHSA-q6w5-jg5q-47vg | @clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR) |
References
History
Thu, 14 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-14T15:42:39.402Z
Reserved: 2024-01-08T04:59:27.373Z
Link: CVE-2024-22206
Updated: 2024-08-01T22:35:34.930Z
Status : Modified
Published: 2024-01-12T20:15:47.420
Modified: 2024-11-21T08:55:47.860
Link: CVE-2024-22206
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA