Published: December 16, 2021 CVE number: CVE-2021-43812Documentation Index
Fetch the complete documentation index at: https://docs-staging.auth0-mintlify.app/llms.txt
Use this file to discover all available pages before exploring further.
Overview
Versions<=1.6.1 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect vulnerability.
Am I affected?
You are affected by this vulnerability if you are using@auth0/nextjs-auth0 version <=1.6.1.
How to fix that?
Upgrade to version>=1.6.2