Description
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.
Remediation
References
Related Vulnerabilities
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-2613)
WordPress Plugin HDW WordPress Video Gallery Multiple Cross-Site Scripting Vulnerabilities (1.2)
ownCloud Improper Access Control Vulnerability (CVE-2016-9462)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Scripting (2.9.7)