Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12633 | Auth0 NextJS SDK v4 Missing Session Invalidation |
Github GHSA |
GHSA-pjr6-jx7r-j4r6 | Auth0 NextJS SDK v4 Missing Session Invalidation |
Thu, 01 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Apr 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid. This issue has been patched in version 4.5.1. | |
| Title | Auth0 NextJS SDK v4 Missing Session Invalidation | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-30T13:17:43.169Z
Reserved: 2025-04-22T22:41:54.912Z
Link: CVE-2025-46344
Updated: 2025-04-30T13:17:37.745Z
Status : Deferred
Published: 2025-04-29T21:15:51.987
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-46344
No data.
OpenCVE Enrichment
Updated: 2025-06-23T19:31:59Z
EUVD
Github GHSA