Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v923-w3x8-wh69

Опубликовано: 02 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

Passport vulnerable to session regeneration when a users logs in or out

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

Пакеты

Наименование

passport

npm
Затронутые версииВерсия исправления

< 0.6.0

0.6.0

EPSS

Процентиль: 62%
0.01058
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 4 лет назад

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

CVSS3: 4.8
redhat
около 4 лет назад

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

CVSS3: 4.8
nvd
около 4 лет назад

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

CVSS3: 4.8
debian
около 4 лет назад

This affects the package passport before 0.6.0. When a user logs in or ...

EPSS

Процентиль: 62%
0.01058
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-384