Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/clerk/javascript/security/advisories/GHSA-q6w5-jg5q-47vg | patch vendor advisory |
https://clerk.com/changelog/2024-01-12 | release notes vendor advisory |
https://github.com/clerk/javascript/releases/tag/%40clerk%2Fnextjs%404.29.3 | patch release notes |