Security controls bypass or absence In @workos-inc/authkit-nextjs
Description
@workos-inc/authkit-nextjs session replay vulnerability
Impact
A user can reuse an expired session by controlling the x-workos-session header.
Patches
Patched in https://github.com/workos/authkit-nextjs/releases/tag/v0.4.2
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 0.4.2 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.