VDB
Sign up
CRITICAL9.0

GHSA-q6w5-jg5q-47vg

@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)

Quick fix

GHSA-q6w5-jg5q-47vg — @clerk/nextjs: upgrade to the fixed version with the command below.

npm install @clerk/nextjs@4.29.3

Details

### Impact Unauthorized access or privilege escalation due to a logic flaw in `auth()` in the App Router or `getAuth()` in the Pages Router.

### Affected Versions All applications that that use `@clerk/nextjs` versions in the range of `>= 4.7.0`,`< 4.29.3` in a Next.js backend to authenticate API Routes, App Router, or Route handlers. Specifically, those that call `auth()` in the App Router or `getAuth()` in the Pages Router. Only the `@clerk/nextjs` SDK is impacted. Other SDKs, including other Javascript-based SDKs, are not impacted.

### Patches Fix included in `@clerk/nextjs@4.29.3`.

### References - https://clerk.com/changelog/2024-01-12 - https://github.com/clerk/javascript/releases/tag/%40clerk%2Fnextjs%404.29.3

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@clerk/nextjs
Introduced in: 4.7.0Fixed in: 4.29.3
Fixnpm install @clerk/nextjs@4.29.3

References