{"id":"GHSA-5wmg-9cvh-qw25","summary":"@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled","details":"### Impact\nRefresh tokens are logged to the console when the disabled by default `debug` flag, is enabled.\n\n### Patches\nPatched in [https://github.com/workos/authkit-nextjs/releases/tag/v0.13.2](https://github.com/workos/authkit-nextjs/releases/tag/v0.13.2)\n","aliases":["CVE-2024-51752"],"modified":"2024-11-05T21:37:24Z","published":"2024-11-05T17:34:23Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-11-05T17:34:23Z","nvd_published_at":"2024-11-05T20:15:15Z","cwe_ids":["CWE-532"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/workos/authkit-nextjs/security/advisories/GHSA-5wmg-9cvh-qw25"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-51752"},{"type":"WEB","url":"https://github.com/workos/authkit-nextjs/commit/15a332632f7560b03cc6d8cc8da24fd2ac931da7"},{"type":"PACKAGE","url":"https://github.com/workos/authkit-nextjs"},{"type":"WEB","url":"https://github.com/workos/authkit-nextjs/releases/tag/v0.13.2"}],"affected":[{"package":{"name":"@workos-inc/authkit-nextjs","ecosystem":"npm","purl":"pkg:npm/%40workos-inc/authkit-nextjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.13.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-5wmg-9cvh-qw25/GHSA-5wmg-9cvh-qw25.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}]}