Interactive prototype · Mock data only · No repositories, cloud accounts, files, or external services are connected
RANGE
4 findings

Vulnerabilities

CVE-2025-29927

Authorization bypass in middleware

Published 21 Mar 2025 View advisory ↗
Critical Public endpoint Production → Staging →
Executive summary
Confirmed production impact

This vulnerability impacts Production. The customer-portal component runs Next.js 15.2.2, uses middleware for authorization, and is deployed behind the public app.northstar.test endpoint.

Last analysed 2 minutes ago
Impact scope

1 affected component · 2 environments

Production
Affected components
customer-portal
Container image · portal:9f31c2
Current
Matched package
next@15.2.2
Source repository
northstar-commerce/customer-portal
Branch main · Commit 9f31c2a
Detected package
next@15.2.2
Fixed version
next@15.2.3
Match confidence
Confirmed inventory
Component and environment evidence
01 · Component
customer-portal
portal:9f31c2
Container image · contains next@15.2.2
02 · Environment
ECS · portal-prod
app.northstar.test
Suggested fix

Upgrade and redeploy the affected component

Upgrade Next.js to 15.2.3 or later, rebuild the customer-portal image, and deploy the new digest to Production. Until deployment is complete, block external requests containing the x-middleware-subrequest header at the edge.

Target · next@15.2.3Component · customer-portalEnvironment · Production