The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid. This issue has been patched in version 4.5.1.
History

Thu, 01 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 21:00:00 +0000

Type Values Removed Values Added
Description The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid. This issue has been patched in version 4.5.1.
Title Auth0 NextJS SDK v4 Missing Session Invalidation
Weaknesses CWE-613
References
Metrics cvssV4_0

{'score': 4.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-29T20:43:41.538Z

Updated: 2025-04-30T13:17:43.169Z

Reserved: 2025-04-22T22:41:54.912Z

Link: CVE-2025-46344

cve-icon Vulnrichment

Updated: 2025-04-30T13:17:37.745Z

cve-icon NVD

Status : Received

Published: 2025-04-29T21:15:51.987

Modified: 2025-04-29T21:15:51.987

Link: CVE-2025-46344

cve-icon Redhat

No data.