GMS-2022-2609: Duplicate of ./npm/next-auth/CVE-2022-31093.yml
(updated )
An attacker can send a request to an app using NextAuth.js with an invalid callbackUrl
query parameter, which internally we convert to a URL
object.
References
Detect and mitigate GMS-2022-2609 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →