-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerable functions are identified based on the descriptions provided, which directly mention auth() and getAuth() as the functions related to the IDOR vulnerability in the @clerk/nextjs package. The exact file paths are not provided, but the functions are part of the @clerk/nextjs package.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| @clerk/nextjs | npm | >= 4.7.0, < 4.29.3 | 4.29.3 |
Ongoing coverage of React2Shell