npm Alert
2612Warning Date
Severity Level
Warning Number
Target Sector
3 August, 2022
● Critical
2022-5087
All
npm has released security update to address a vulnerability in the following product:
- NextAuth.js before 4.10.3 and 3.29.10
Attacker could exploit this vulnerability by doing the following:
- Bypass of a protection mechanism (authorization bypass)
The CERT team encourages users to review npm security advisory and apply the necessary updates: