Skip to content

Open Redirect in Next.js versions 9.5.0 to 9.5.3

High
sr229 published GHSA-8w2r-w8vg-p92v Oct 9, 2020

Package

npm nextjs (npm)

Affected versions

d4674b2c1535ce54ab5bbea0bf0cd1c6e0d98a94

Patched versions

b63180c185215784c91558c9cf223e7610ec9f06

Description

Impact

This impacts all Nimi users who self-hosts their own versions that uses Next.js 9.5.0 to 9.5.3

Patches

Sync your copies to b63180c As soon as possible.

Workarounds

N/A

References

GHSA-x56p-c8cg-q435

For more information

See: https://github.com/vercel/next.js/releases/tag/v9.5.4

Severity

High

CVE ID

CVE-2020-15242

Weaknesses

No CWEs