The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid. This issue has been patched in version 4.5.1.
Metrics
Affected Vendors & Products
References
History
Thu, 01 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 29 Apr 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid. This issue has been patched in version 4.5.1. | |
Title | Auth0 NextJS SDK v4 Missing Session Invalidation | |
Weaknesses | CWE-613 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-04-29T20:43:41.538Z
Updated: 2025-04-30T13:17:43.169Z
Reserved: 2025-04-22T22:41:54.912Z
Link: CVE-2025-46344

Updated: 2025-04-30T13:17:37.745Z

Status : Received
Published: 2025-04-29T21:15:51.987
Modified: 2025-04-29T21:15:51.987
Link: CVE-2025-46344

No data.