QID 995872
Date Published: 2023-11-16
QID 995872: NodeJs (Npm) Security Update for @sentry/nextjs (GHSA-2rmr-xw8m-22q9)
An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This could open door for other attack vectors:
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-2rmr-xw8m-22q9 for updates and patch information.
Vendor References
- GHSA-2rmr-xw8m-22q9 -
github.com/advisories/GHSA-2rmr-xw8m-22q9
CVEs related to QID 995872
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2rmr-xw8m-22q9 | @sentry/nextjs |
|