A Server-Side Request Forgery (SSRF) vulnerability exists in the Next.js framework. An unauthenticated remote attacker may exploit this vulnerability to cause the server to issue requests to arbitrary internal or external hosts or perform Open Redirect attacks.
Target Audience:
Organizations developing or hosting web applications using the Next.js framework.
Risk Assessment:
High risk of unauthorized access to internal network resources and disclosure of sensitive information.
Impact Assessment:
Potential High impact on Confidentiality of the System.
The information provided herein is on "as is" basis, without warranty of any kind.