CVE-2024-29901: @workos-inc/authkit-nextjs session replay vulnerability
A user can reuse an expired session by controlling the x-workos-session
header.
References
- github.com/advisories/GHSA-35w3-6qhc-474v
- github.com/workos/authkit-nextjs
- github.com/workos/authkit-nextjs/commit/6c3f4f3179d66cbb15de3962792083ff3b244a01
- github.com/workos/authkit-nextjs/releases/tag/v0.4.2
- github.com/workos/authkit-nextjs/security/advisories/GHSA-35w3-6qhc-474v
- nvd.nist.gov/vuln/detail/CVE-2024-29901
Detect and mitigate CVE-2024-29901 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →