Vulnerabilities/

@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)

Severity:
High

Description

Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router.

Recommendation

Update the @clerk/nextjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@clerk/nextjs
Anything's wrong? Let us know Last updated on January 15, 2024