CVE-2024-51479
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-51479 is a vulnerability affecting Next.js, a React framework used for building full-stack web applications. In certain versions, authorization checks based on middleware and pathnames can be bypassed for pages directly under the application's root directory. For instance, an application at "https://example.com/" would not be affected, while "https://example.com/foo" would be vulnerable. This issue has been addressed in Next.js versions 14.2.15 and later. Vercel-hosted applications have already been mitigated, regardless of their Next.js version. No official workarounds are available for unaffected versions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Vercel Inc.