Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-25896

Опубликовано: 01 июл. 2022
Источник: debian
EPSS Низкий

Описание

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
passportjsfixed0.6.0+~1.0.0-1package
passportjsno-dsabullseyepackage
passportjsno-dsabusterpackage

Примечания

  • https://github.com/jaredhanson/passport/commit/42630cbd1ffd44d146ff96f0a4be6f3c12f81d75 (v0.6.0)

  • https://github.com/jaredhanson/passport/pull/900

  • https://snyk.io/vuln/SNYK-JS-PASSPORT-2840631

EPSS

Процентиль: 38%
0.00164
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 3 лет назад

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

CVSS3: 4.8
redhat
больше 3 лет назад

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

CVSS3: 4.8
nvd
больше 3 лет назад

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

CVSS3: 4.8
github
больше 3 лет назад

Passport vulnerable to session regeneration when a users logs in or out

EPSS

Процентиль: 38%
0.00164
Низкий