CVE-2024-51753: @workos-inc/authkit-remix refresh tokens are logged when the debug flag is enabled
Refresh tokens are logged to the console when the disabled by default debug
flag, is enabled.
References
- github.com/advisories/GHSA-v2qh-f584-6hj8
- github.com/workos/authkit-remix
- github.com/workos/authkit-remix/commit/32d5bcd54c795c1e2a3204f8e3977ab9ad57ec06
- github.com/workos/authkit-remix/releases/tag/v0.4.1
- github.com/workos/authkit-remix/security/advisories/GHSA-v2qh-f584-6hj8
- nvd.nist.gov/vuln/detail/CVE-2024-51753
Detect and mitigate CVE-2024-51753 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →