GHSA-pjr6-jx7r-j4r6

Suggest an improvement
Source
https://github.com/advisories/GHSA-pjr6-jx7r-j4r6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-pjr6-jx7r-j4r6/GHSA-pjr6-jx7r-j4r6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pjr6-jx7r-j4r6
Aliases
Published
2025-04-29T18:54:49Z
Modified
2025-04-30T17:25:56Z
Severity
  • 4.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Auth0 NextJS SDK v4 Missing Session Invalidation
Details

Overview

Auth0 NextJS v4.0.1 to v4.5.0 does not invoke .setExpirationTime when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid.

Am I Affected?

You are affected if you are using Auth0 NextJS SDK v4.

Fix

Upgrade to v4.5.1.

Database specific
{
    "cwe_ids":  [
        "CWE-613"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-04-29T18:54:49Z",
    "nvd_published_at":  "2025-04-29T21:15:51Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / @auth0/nextjs-auth0

Package

Name
@auth0/nextjs-auth0
View open source insights on deps.dev
Purl
pkg:npm/%40auth0/nextjs-auth0

Affected ranges

Type
SEMVER
Events
Introduced
4.0.1
Fixed
4.5.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-pjr6-jx7r-j4r6/GHSA-pjr6-jx7r-j4r6.json"