CVE-2024-51479

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 17, 2024
CWE ID 285

Summary

CVE-2024-51479 is a vulnerability affecting Next.js, a React framework used for building full-stack web applications. In certain versions, authorization checks based on middleware and pathnames can be bypassed for pages directly under the application's root directory. For instance, an application at "https://example.com/" would not be affected, while "https://example.com/foo" would be vulnerable. This issue has been addressed in Next.js versions 14.2.15 and later. Vercel-hosted applications have already been mitigated, regardless of their Next.js version. No official workarounds are available for unaffected versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share