Description
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
Remediation
References
https://github.com/zeit/next.js/releases/tag/7.0.2
Related Vulnerabilities
CVE-2018-16115 Vulnerability in maven package com.typesafe.akka:akka-actor_2.12
CVE-2022-45390 Vulnerability in maven package io.loader:loaderio-jenkins-plugin
CVE-2019-10337 Vulnerability in maven package org.jenkins-ci.plugins:token-macro
CVE-2023-37962 Vulnerability in maven package io.jenkins.plugins:benchmark-evaluator
CVE-2021-27738 Vulnerability in maven package org.apache.kylin:kylin-stream-coordinator