CVE-2024-22206

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:clerk:javascript:*:*:*:*:*:node.js:*:*

History

22 Jan 2024, 18:38

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-12 20:15

Updated : 2024-02-05 00:22


NVD link : CVE-2024-22206

Mitre link : CVE-2024-22206

CVE.ORG link : CVE-2024-22206


JSON object : View

Products Affected

clerk

  • javascript
CWE
CWE-284

Improper Access Control

CWE-287

Improper Authentication

CWE-639

Authorization Bypass Through User-Controlled Key