Описание
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| passportjs | fixed | 0.6.0+~1.0.0-1 | package | |
| passportjs | no-dsa | bullseye | package | |
| passportjs | no-dsa | buster | package |
Примечания
https://github.com/jaredhanson/passport/commit/42630cbd1ffd44d146ff96f0a4be6f3c12f81d75 (v0.6.0)
https://github.com/jaredhanson/passport/pull/900
https://snyk.io/vuln/SNYK-JS-PASSPORT-2840631
EPSS
Связанные уязвимости
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
Passport vulnerable to session regeneration when a users logs in or out
EPSS