CVE-2023-46298
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 22, 2023
Updated: Oct 28, 2023
Summary
CVE-2023-46298 refers to a vulnerability in Next.js versions before 13.4.20-canary.13. This issue arises due to the lack of a cache-control header during empty prefetch responses. Consequently, CDNs may inadvertently cache these responses, leading to a denial of service for all users requesting the same URL through that CDN. This vulnerability can potentially disrupt access to affected websites, highlighting the importance of proper cache-control settings.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share