CVE-2024-22206 CRITICAL

CVE-2024-22206: @clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)

Vendor Clerk
Product javascript
Weakness CWE-284
Published January 12, 2024
Last update November 14, 2024

CVSS base score

9.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.

Key dates

02Disclosure timeline

January 12, 2024 CVE published
November 14, 2024 Record updated