GHSA-q6w5-jg5q-47vg
@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)
Quick fix
GHSA-q6w5-jg5q-47vg — @clerk/nextjs: upgrade to the fixed version with the command below.
npm install @clerk/nextjs@4.29.3Details
### Impact Unauthorized access or privilege escalation due to a logic flaw in `auth()` in the App Router or `getAuth()` in the Pages Router.
### Affected Versions All applications that that use `@clerk/nextjs` versions in the range of `>= 4.7.0`,`< 4.29.3` in a Next.js backend to authenticate API Routes, App Router, or Route handlers. Specifically, those that call `auth()` in the App Router or `getAuth()` in the Pages Router. Only the `@clerk/nextjs` SDK is impacted. Other SDKs, including other Javascript-based SDKs, are not impacted.
### Patches Fix included in `@clerk/nextjs@4.29.3`.
### References - https://clerk.com/changelog/2024-01-12 - https://github.com/clerk/javascript/releases/tag/%40clerk%2Fnextjs%404.29.3
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/clerk/javascript/security/advisories/GHSA-q6w5-jg5q-47vg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-22206[ADVISORY]
- https://clerk.com/changelog/2024-01-12[WEB]
- https://github.com/clerk/javascript[PACKAGE]
- https://github.com/clerk/javascript/releases/tag/%40clerk%2Fnextjs%404.29.3[WEB]