Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a gated action to proceed for a user who does not satisfy the full set of requested conditions. This call shape can be bypassed if certain conditions are met: a has() or auth.protect() call that combines a reverification check with any of role, permission, feature, or plan, or that combines a billing check (feature or plan) with a role or permission check. This vulnerability is fixed in @clerk/clerk-js 5.125.10 and 6.7.5.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.17.11CPE matchmatch criteria | cpe:2.3:a:clerk:clerk\/astro:*:*:*:*:*:node.js:*:* | ||
>= 3.0.0, < 3.0.18CPE matchmatch criteria | cpe:2.3:a:clerk:clerk\/astro:*:*:*:*:*:node.js:*:* | ||
>= 2.0.0, < 2.33.3CPE matchmatch criteria | cpe:2.3:a:clerk:clerk\/backend:*:*:*:*:*:node.js:*:* | ||
>= 3.0.0, < 3.2.14CPE matchmatch criteria | cpe:2.3:a:clerk:clerk\/backend:*:*:*:*:*:node.js:*:* | ||
>= 1.3.5, < 2.9.15CPE matchmatch criteria | cpe:2.3:a:clerk:clerk\/chrome-extension:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.