Rewterz
Rewterz Threat Alert – DarkCrystal RAT (DCRat) Targeting Ukrainian Telecommunications Operators – Active IOCs- Russian-Ukrainian Cyber Warfare
June 27, 2022
Rewterz
Rewterz Threat Alert – APT Group Gamaredon – Active IOCs
June 28, 2022

Rewterz Threat Advisory – CVE-2022-31093 – Node.js next-auth module Vulnerability

Severity

High

Analysis Summary

CVE-2022-31093

Node.js next-auth module is vulnerable to a denial of service, caused by improper handling of callbackUrl. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause an unhandled error to be thrown.

Impact

  • Denial of Service

Indicators Of Compromise

CVE

  • CVE-2022-31093

Affected Vendors

  • Node.js

Affected Products

  • Node.js Node.js
  • Node.js next-auth 3.29.4
  • Node.js next-auth 4.4.0

Remediation

Upgrade to the latest version of next-auth, available from the nextauthjs GIT Repository.

next-auth Security Advisory