SCA: security update for @auth0/nextjs-auth0 (GHSA-954c-jjx6-cxv7)

medium Tenable Cloud Security Plugin ID 413042

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions
before and including `1.4.1` are vulnerable to reflected XSS. An attacker can execute arbitrary code by
providing an XSS payload in the `error` query parameter which is then processed by the callback handler as
an error message. You are affected by this vulnerability if you are using `@auth0/nextjs-auth0` version
`1.4.1` or lower **unless** you are using custom error handling that does not return the error message in
an HTML response. Upgrade to version `1.4.1` to resolve. The fix adds basic HTML escaping to the error
message and it should not impact your users. (CVE-2021-32702)

See Also

https://github.com/advisories/GHSA-954c-jjx6-cxv7

Plugin Details

Severity: Medium

ID: 413042

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 8.67

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2021-32702

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/25/2021

Vulnerability Publication Date: 6/25/2021

Reference Information

CVE: CVE-2021-32702

cwe: CWE-79