WRITEUP

WRITEUP
Exploit for CVE-2024-29901 - AuthKit <0.4.2 - SSRF
AI Analysis

The patch addresses an authentication bypass vulnerability in WorkOS AuthKit for Next.js by ensuring the `x-workos-session` header is always controlled and deleted when no session exists. The fix prevents unauthorized access by enforcing proper header management during session validation.

Attack Type
auth_bypass
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
T1550 - Use Alternate Authentication Material
Loading exploit code...
Download ZIP Password: eip
Vulnerability
CVE-2024-29901
AuthKit <0.4.2 - SSRF
MEDIUM
CVSS 4.8