npmframework

Overview

Canonical component data stored by Polaris.

Version

4.22.5

Package Manager

npm

Type

framework

Systems

1

Licenses
ISC
Direct Dependencies

10

Technology

Not linked

External Signals
deps.dev endoflife.date OSV.dev
Package URL

pkg:npm/[email protected]

Maintenance

Derived from available component and registry data

Aging
Confidence

Medium

Version Age

1094 days

Update Status

Minor update available

Recent Activity

Yes

Reasons
Very old versionMature versionMinor available

Lifecycle

Source: endoflife.date

Unknown
No lifecycle match available
The mapped product was not available from the third-party lifecycle source.
Open endoflife.date

Registry

Source: deps.dev

Available
Ecosystem

npm

Latest Version

4.24.15

Published

8/8/2023

Recent Releases

8

Advisories

5

Open deps.dev

Known Vulnerabilities

Source: OSV.dev

5 found

GHSA-5jpx-9hw9-2fx4

NextAuthjs Email misdelivery Vulnerability

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected Versions
all versions before 4.24.12>= 5.0.0-beta.0, before 5.0.0-beta.30
Open advisory

GHSA-7rqj-j65f-68wh

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Versions
>= 0.1.0, before 0.41.3>= 4.10.3, before 4.24.15>= 5.0.0-beta.1, before 5.0.0-beta.32
Open advisory

GHSA-v64w-49xw-qq89

Possible user mocking that bypasses basic authentication

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Versions
all versions before 4.24.5
Open advisory

GHSA-x445-f3h2-j279

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected Versions
all versions before 0.41.3>= 5.0.0-beta.1, before 5.0.0-beta.32all versions before 4.24.15
Open advisory

GHSA-xmf8-cvqr-rfgj

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
>= 0.1.0, before 0.41.3>= 5.0.0-beta.0, before 5.0.0-beta.32>= 4.0.6, before 4.24.15
Open advisory
Open OSV.dev

Security

Source: OpenSSF Scorecard

Unavailable
No security scorecard available
This component does not have a repository reference for OpenSSF Scorecard lookup.

Dependencies

10 direct dependencies

Global view