漏洞描述
Next.Js, inferior to version 14.1.1, have its image optimization built-in component prone to SSRF.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.assetnote.iohttps://www.assetnote.io/resources/research/digging-for-ssrf-in-nextjs-apps↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2024-34351↗github.comhttps://github.com/vercel/next.js/security/advisories/GHSA-fr5h-rqp8-mj6g↗github.comhttps://github.com/vercel/next.js/commit/8f7a6ca7d21a97bc9f7a1bbe10427b5ad74b9085↗github.comhttps://github.com/vercel/next.js/pull/62561↗