npm Alert
2342Warning Date
Severity Level
Warning Number
Target Sector
22 June, 2022
● High
2022-4984
All
Description:
npm has released a security update to address a vulnerability in the following products:
- next-auth
- < 3.29.5
- >= 4.0.0, < 4.5.0
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Improper Handling of `callbackUrl` parameter
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary update: