WRITEUP
WRITEUP
Exploit for CVE-2024-29901
- AuthKit <0.4.2 - SSRF
AI Analysis
The patch addresses an authentication bypass vulnerability in WorkOS AuthKit for Next.js by ensuring the `x-workos-session` header is always controlled and deleted when no session exists. The fix prevents unauthorized access by enforcing proper header management during session validation.
Attack Type
auth_bypass
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
Click anywhere or press Esc to close