2024 Clerk — CVE-2024-22206 IDOR in @clerk/nextjs
Data compromised
Potential: unauthorized user impersonation; privilege escalation
Technical writeup
Critical IDOR in auth()/getAuth() (versions 4.7.0–4.29.2). Allowed unauthorized access or privilege escalation to act on behalf of other users. Patched 4.29.3. Cloudflare, Netlify, Vercel deployed mitigations.
Root cause
Improper access control; insecure direct object reference