Insecure session management In @workos-inc/authkit-nextjs
Description
@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled
Impact
Refresh tokens are logged to the console when the disabled by default debug flag, is enabled.
Patches
Patched in https://github.com/workos/authkit-nextjs/releases/tag/v0.13.2
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 0.13.2 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.