Vulnerabilities/

Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint

Severity:
Medium

Description

An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user.

Recommendation

Update the @sentry/nextjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@sentry/nextjs
Anything's wrong? Let us know Last updated on November 17, 2023

This issue is available in SmartScanner Professional

See Pricing