CVE-2021-43803
Unexpected server crash in Next.js
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the deployment must use Next.js versions above 11.1.0 and below 12.0.5, Node.js above 15.0.0, and next start or a custom server. Deployments on Vercel are not affected, along with similar environments where invalid requests are filtered before reaching Next.js. Versions 12.0.5 and 11.1.3 contain patches for this issue.
Next.js es un framework de React. En las versiones de Next.js anteriores a 12.0.5 o 11.1.3, las direcciones URL no válidas o malformadas podrían conllevar a un bloqueo del servidor. Para verse afectado por este problema, el despliegue debe usar versiones de Next.js superiores a 11.1.0 y anteriores a 12.0.5, Node.js versiones posteriores a 15.0.0, y el siguiente inicio o un servidor personalizado. Los despliegues en Vercel no están afectados, junto con entornos similares en los que las peticiones no válidas son filtradas antes de llegar a Next.js. Las versiones 12.0.5 y 11.1.3 contienen parches para este problema
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-16 CVE Reserved
- 2021-12-09 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://github.com/vercel/next.js/releases/tag/v11.1.3 | Release Notes | |
https://github.com/vercel/next.js/releases/v12.0.5 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vercel Search vendor "Vercel" | Next.js Search vendor "Vercel" for product "Next.js" | >= 11.1.0 < 11.1.3 Search vendor "Vercel" for product "Next.js" and version " >= 11.1.0 < 11.1.3" | node.js |
Affected
| in | Nodejs Search vendor "Nodejs" | Node.js Search vendor "Nodejs" for product "Node.js" | > 15.0.0 Search vendor "Nodejs" for product "Node.js" and version " > 15.0.0" | - |
Safe
|
Vercel Search vendor "Vercel" | Next.js Search vendor "Vercel" for product "Next.js" | >= 12.0.0 < 12.0.5 Search vendor "Vercel" for product "Next.js" and version " >= 12.0.0 < 12.0.5" | node.js |
Affected
| in | Nodejs Search vendor "Nodejs" | Node.js Search vendor "Nodejs" for product "Node.js" | > 15.0.0 Search vendor "Nodejs" for product "Node.js" and version " > 15.0.0" | - |
Safe
|