4 findings
Vulnerabilities
Executive summary
Confirmed production impactThis vulnerability impacts Production. The customer-portal component runs Next.js 15.2.2, uses middleware for authorization, and is deployed behind the public app.northstar.test endpoint.
Last analysed 2 minutes ago
Impact scope
1 affected component · 2 environments
Affected components
customer-portal
Container image · portal:9f31c2
Matched package
next@15.2.2
↳
Source repository
northstar-commerce/customer-portal
Branch main · Commit 9f31c2a
Detected package
next@15.2.2
Fixed version
next@15.2.3
Match confidence
Confirmed inventory
Component and environment evidence
01 · Component
customer-portal
portal:9f31c2
Container image · contains next@15.2.2
02 · Environment
ECS · portal-prod
app.northstar.test
Suggested fix
Upgrade and redeploy the affected component
Upgrade Next.js to 15.2.3 or later, rebuild the customer-portal image, and deploy the new digest to Production. Until deployment is complete, block external requests containing the x-middleware-subrequest header at the edge.
Target · next@15.2.3Component · customer-portalEnvironment · Production