Cross-site request forgery In next
Description
Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass
In Next.js App Router applications built with webpack, metadata image routes such as opengraph-image and twitter-image ignore the dynamicParams route segment option. An attacker can request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams().
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel10 | - | - | |
rpm rhel7 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel8 | - | - | |
npm | 16.3.8 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.