chore(deps): update dependency next-auth to v5.0.0-beta.30 [security] #293
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
RicardoGEsteves all-non-major update, dependency next-auth to v5.0.0-beta.30
This PR contains the following updates:
5.0.0-beta.25->5.0.0-beta.30GitHub Vulnerability Alerts
GHSA-5jpx-9hw9-2fx4
Summary
NextAuth.js's email sign-in can be forced to deliver authentication emails to an attacker-controlled mailbox due to a bug in
nodemailer's address parser used by the project (fixed innodemailerv7.0.7). A crafted input such as:is parsed incorrectly and results in the message being delivered to
e@attacker.com(attacker) instead of"<e@attacker.com>@​victim.com"(the intended recipient atvictim.com) in violation of RFC 5321/5322 semantics. This allows an attacker to receive login/verification links or other sensitive emails intended for the victim.Affected NextAuthjs Version
POC
Example Setup showing misdelivery of email
Mitigation
Update to nodemailer 7.0.7
Credits
https://zeropath.com/ Helped identify this security issue
Release Notes
nextauthjs/next-auth (next-auth)
v5.0.0-beta.30Compare Source
v5.0.0-beta.29Compare Source
What's Changed
New Contributors
Full Changelog: https://github.com/nextauthjs/next-auth/compare/next-auth@5.0.0-beta.28...next-auth@5.0.0-beta.29
v5.0.0-beta.28Compare Source
What's Changed
Credentialsprovider by @halvaradop in #12873PrismaClientKnownRequestErrorfor edge runtime compatibility by @twinh in #12755New Contributors
Full Changelog: https://github.com/nextauthjs/next-auth/compare/next-auth@5.0.0-beta.27...next-auth@5.0.0-beta.28
v5.0.0-beta.27Compare Source
What's Changed
Full Changelog: https://github.com/nextauthjs/next-auth/compare/next-auth@5.0.0-beta.26...next-auth@5.0.0-beta.27
v5.0.0-beta.26What's Changed
accountin callbacks. by @w9 in #12017cookiepackage by @balazsorban44 in #12177cookieuntil it has an ESM build by @balazsorban44 in #12248formatby @halvaradop in #12302OAuthsection by @halvaradop in #11954redirectToby @NazgoooAtanasov in #12315verficationtoverificationby @nrjdalal in #12376expresslabel for pr-labeler GHA by @bjohansebas in #12343form_postproviders. by @garshythoel in #12309awaitto some tests. by @KostyaTretyak in #12439no-floating-promisesrule andprojectService: trueto eslint config by @KostyaTretyak in #12440parseProviders()whenproviderIdnot found in config by @KostyaTretyak in #12438/sponsorsby @ndom91 in #12575adapter.ts->adapters.tsin@auth/sveltekitby @emme1444 in #12503New Contributors
Full Changelog: https://github.com/nextauthjs/next-auth/compare/next-auth@5.0.0-beta.24...next-auth@5.0.0-beta.26
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.