UNKNOWN npm
@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled
GHSA-5wmg-9cvh-qw25 · CVE-2024-51752
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Refresh tokens are logged to the console when the disabled by default debug flag, is enabled.
Patches
Patched in https://github.com/workos/authkit-nextjs/releases/tag/v0.13.2
References
- WEB https://github.com/workos/authkit-nextjs/security/advisories/GHSA-5wmg-9cvh-qw25
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-51752
- WEB https://github.com/workos/authkit-nextjs/commit/15a332632f7560b03cc6d8cc8da24fd2ac931da7
- PACKAGE https://github.com/workos/authkit-nextjs
- WEB https://github.com/workos/authkit-nextjs/releases/tag/v0.13.2
Ready to move
Start Securing
Free, no credit card | First findings in minutes