Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-62vx-hpcr-m9ch

Опубликовано: 20 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.6

Описание

@perfood/couch-auth may expose session tokens, passwords

Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, potentially leading to session hijacking.

Пакеты

Наименование

@perfood/couch-auth

npm
Затронутые версииВерсия исправления

<= 0.21.2

Отсутствует

EPSS

Процентиль: 6%
0.00023
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-316

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, potentially leading to session hijacking.

EPSS

Процентиль: 6%
0.00023
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-316