CVE-2024-22206

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.
CVSS

No CVSS.

Configurations

No configuration.

Information

Published : 2024-01-12 20:15

Updated : 2024-01-12 20:15


NVD link : CVE-2024-22206

Mitre link : CVE-2024-22206


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key

CWE-287

Improper Authentication

CWE-284

Improper Access Control