VDB
Sign up
MEDIUM

GHSA-pjr6-jx7r-j4r6

Auth0 NextJS SDK v4 Missing Session Invalidation

Quick fix

GHSA-pjr6-jx7r-j4r6 — @auth0/nextjs-auth0: upgrade to the fixed version with the command below.

npm install @auth0/nextjs-auth0@4.5.1

Details

### Overview Auth0 NextJS `v4.0.1` to `v4.5.0` does not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid.

### Am I Affected? You are affected if you are using Auth0 NextJS SDK v4.

### Fix Upgrade to `v4.5.1`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@auth0/nextjs-auth0
Introduced in: 4.0.1Fixed in: 4.5.1
Fixnpm install @auth0/nextjs-auth0@4.5.1

References