Technical information leak In firefox
Description
A flaw was found in Next.js. Unauthenticated users can exploit this vulnerability by accessing publicly served client artifacts, which may disclose Server Action IDs. This bypasses authentication on pages where these endpoints are used, leading to information disclosure. While primarily an enumeration primitive, this disclosure can increase overall risk when combined with other vulnerabilities.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 15.5.21, 16.2.11 | ||
rpm rhel10 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
rpm rhel7 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5.