The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Tue, 05 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 05 Nov 2024 19:30:00 +0000

Type Values Removed Values Added
Description The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Refresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-nextjs
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-05T19:16:41.831Z

Updated: 2024-11-05T20:15:07.923Z

Reserved: 2024-10-31T14:12:45.791Z

Link: CVE-2024-51752

cve-icon Vulnrichment

Updated: 2024-11-05T20:15:03.842Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-05T20:15:15.167

Modified: 2024-11-06T18:17:17.287

Link: CVE-2024-51752

cve-icon Redhat

No data.