Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4862 | NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1 provider. Versions 3.29.3 and 4.3.3 contain a patch for this issue. The maintainers recommend adding a certain configuration to one's `callbacks` option as a workaround for those unable to upgrade. |
Github GHSA |
GHSA-q2mx-j4x2-2h74 | URL Redirection to Untrusted Site ('Open Redirect') in next-auth |
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:23:37.970Z
Reserved: 2022-04-13T00:00:00.000Z
Link: CVE-2022-29214
Updated: 2024-08-03T06:17:54.257Z
Status : Modified
Published: 2022-05-21T00:15:11.853
Modified: 2024-11-21T06:58:44.093
Link: CVE-2022-29214
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA