Fix React Server Components CVE vulnerabilities #92
Pull Request #92 Alerts: Complete with warnings
| Report | Status | Message |
|---|---|---|
| PR #92 Alerts | Found 1 project alert |
Pull request alerts notify when new issues are detected between the diff of the pull request and it's target branch.
Details
Caution
Review the following alerts detected in dependencies.
According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
| Action | Severity | Alert (click "▶" to expand/collapse) |
|---|---|---|
| Block | Critical CVE: Authorization Bypass in Next.js MiddlewareCVE: GHSA-f82v-jwr5-mffw Authorization Bypass in Next.js Middleware (CRITICAL) Affected versions: >= 13.0.0 < 13.5.9; >= 14.0.0 < 14.2.25; >= 15.0.0 < 15.2.3; >= 11.1.4 < 12.3.5 Patched version: 15.2.3 From: package.json → ℹ Read more on: This package | This alert | What is a critical CVE?
|