CVE-2024-29901
29.03.2024, 16:15
The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2.Enginsight
Vendor | Product | Version |
---|---|---|
workos | authkit | 𝑥 < 0.4.2 |
𝑥
= Vulnerable software versions
References