-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency next to v14 [SECURITY] #714
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/npm-next-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
2 times, most recently
from
May 14, 2024 15:07
11c61e0
to
84fa9a0
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
3 times, most recently
from
May 29, 2024 22:40
6c8a49e
to
387300e
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
6 times, most recently
from
June 5, 2024 12:45
95f31bf
to
eb733c4
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
2 times, most recently
from
June 18, 2024 04:26
503c317
to
84dfcbe
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
6 times, most recently
from
June 22, 2024 15:34
46e27ce
to
7d3bb0f
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
3 times, most recently
from
July 1, 2024 22:36
89b1615
to
071a84c
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
2 times, most recently
from
July 8, 2024 22:00
d510a72
to
a50096b
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
2 times, most recently
from
July 16, 2024 22:43
87c7f80
to
5498d24
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
3 times, most recently
from
July 24, 2024 15:45
280ace5
to
ac4b854
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
from
August 2, 2024 12:15
b4e4a25
to
c7113c7
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
2 times, most recently
from
August 16, 2024 21:56
b9138fa
to
8b11219
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
4 times, most recently
from
August 21, 2024 21:50
36dc8a4
to
eee5aed
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
4 times, most recently
from
September 2, 2024 00:24
b82ae77
to
4ac17c1
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
3 times, most recently
from
September 9, 2024 21:51
3d05336
to
a029557
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
3 times, most recently
from
September 19, 2024 22:49
368fe28
to
b81d478
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
7 times, most recently
from
September 28, 2024 00:28
853a31e
to
b7c5a51
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
4 times, most recently
from
October 9, 2024 03:35
c3fe00a
to
fe52f8b
Compare
renovate
bot
force-pushed
the
renovate/npm-next-vulnerability
branch
from
October 11, 2024 18:49
fe52f8b
to
530cdf8
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
13.5.6
->14.1.1
GitHub Vulnerability Alerts
CVE-2024-34351
Impact
A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions by security researchers at Assetnote. If the
Host
header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself.Prerequisites
<14.1.1
) is running in a self-hosted* manner./
.* Many hosting providers (including Vercel) route requests based on the Host header, so we do not believe that this vulnerability affects any Next.js applications where routing is done in this manner.
Patches
This vulnerability was patched in #62561 and fixed in Next.js
14.1.1
.Workarounds
There are no official workarounds for this vulnerability. We recommend upgrading to Next.js
14.1.1
.Credit
Vercel and the Next.js team thank Assetnote for responsibly disclosing this issue to us, and for working with us to verify the fix. Thanks to:
Adam Kues - Assetnote
Shubham Shah - Assetnote
CVE-2024-46982
Impact
By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it could coerce Next.js to cache a route that is meant to not be cached and send a
Cache-Control: s-maxage=1, stale-while-revalidate
header which some upstream CDNs may cache as well.To be potentially affected all of the following must apply:
pages/dashboard.tsx
notpages/blog/[slug].tsx
The below configurations are unaffected:
Patches
This vulnerability was resolved in Next.js v13.5.7, v14.2.10, and later. We recommend upgrading regardless of whether you can reproduce the issue or not.
Workarounds
There are no official or recommended workarounds for this issue, we recommend that users patch to a safe version.
Credits
Release Notes
vercel/next.js (next)
v14.1.1
Compare Source
Note: this is a backport release for critical bug fixes -- this does not include all pending features/changes on canary
Core Changes
Credits
Huge thanks to @huozhi, @shuding, @Ethan-Arrowood, @styfle, @ijjk, @ztanner, @balazsorban44, @kdy1, and @williamli for helping!
v14.1.0
Compare Source
v14.0.4
Compare Source
v14.0.3
Compare Source
v14.0.2
Compare Source
v14.0.1
Compare Source
Core Changes
8c8ee9e
to0c63487
and types: #57772Documentation Changes
Example Changes
with-youtube-embed
example: #57367with-google-maps-embed
example: #57365Misc Changes
create-next-app
: #57262Credits
Huge thanks to @dijonmusters, @sokra, @philwolstenholme, @IgorKowalczyk, @housseindjirdeh, @Zoe-Bot, @HanCiHu, @JackHowa, @goncy, @hirotomoyamada, @pveyes, @yeskunall, @vinaykulk621, @ChendayUP, @leerob, @dvoytenko, @mknichel, @ijjk, @hmaesta, @ajz003, @its-kunal, @joelhooks, @blurrah, @tariknh, @Vinlock, @Nayeem-XTREME, @aziyatali, @aspehler, @huozhi, @ztanner, @ForsakenHarmony, @moka-ayumu, and @gnoff for helping!
v14.0.0
Compare Source
v13.5.7
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.