|
|
|
|
|
|
|
Hello,
|
|
|
|
The Clerk team recently identified and patched a critical security vulnerability in the @clerk/nextjs SDK that allows malicious actors to gain privileged access or act-on-behalf-of other users.
|
|
|
|
If you use @clerk/nextjs, please upgrade immediately to 4.29.3.
|
|
|
|
Only the Next.js SDK is impacted. Other SDKs, including other Javascript-based SDKs, are not impacted.
|
|
|
Complete details about the vulnerability have been published in our changelog, including measures that infrastructure providers have taken to help mitigate attacks.
|
|
|
|
Although we are not aware of the vulnerability having ever been exploited, we unfortunately cannot be sure without access to the Next.js server’s logs. Detailed instructions for inspecting logs for an attack will be made available to impacted customers who request them, but will not be published publicly. Please respond to this email if you would like to receive those instructions.
|
|
|
|
Security is Clerk’s most important responsibility, and we are continually improving our processes to ensure your application and your users remain safe. If you have questions or concerns, please do not hesitate to respond to this email.
|
|
|
|
Thank you
|
|
|
|
|
|
© 2024 Clerk Inc, San Francisco, CA 94107
|
|
|
|