Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a …
高危 CVSS 8.2
摘要
Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in version 16.2.11.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/vercel/next.js/commit/6bf4df14508ad6c0cd46af50c6051ee42f2d9151 Patch
- https://github.com/vercel/next.js/pull/96014 Issue Tracking
- https://github.com/vercel/next.js/releases/tag/v16.2.11 Product
- https://github.com/vercel/next.js/security/advisories/GHSA-6gpp-xcg3-4w24 Vendor Advisory
时间线
- nvd_ingest NVD