Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Better Auth 1.7.7: Kritische Magic-Link-Sicherheitslücke behoben
Better Auth v1.7.7 behebt eine kritische Magic-Link-Sicherheitslücke zur Kontoübernahme, die Ignorierung von disableSignUp bei ID-Token-Anmeldungen, die Annahme von Sign-in-State als Provider-Profil im OAuth Proxy sowie mehrere Fehler bei JSON-Content-Type-Headern und der Aktualisierung der aktiven Organisation; Server mit gemeinsamem Verification-Speicher müssen gemeinsam aktualisiert werden, neue Magic Links angefordert und ausstehende OAuth/SAML-Anmeldungen neu gestartet werden.
better-auth
Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.
Bug Fixes
- Fixed a critical Magic Link account-takeover vulnerability. (#11494)
- Fixed ID-token sign-in ignoring the social provider’s
disableSignUpsetting. (#11491) - Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494) Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
- Fixed CAPTCHA errors missing the JSON
Content-Typeheader. (#11476) - Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
- Fixed rate-limit errors missing the JSON
Content-Typeheader. (#11469) …