Логотип exploitDog
bind:CVE-2025-60794
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-60794

Количество 2

Количество 2

nvd логотип

CVE-2025-60794

3 месяца назад

Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, potentially leading to session hijacking.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-62vx-hpcr-m9ch

3 месяца назад

@perfood/couch-auth may expose session tokens, passwords

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-60794

Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, potentially leading to session hijacking.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-62vx-hpcr-m9ch

@perfood/couch-auth may expose session tokens, passwords

0%
Низкий
3 месяца назад

Уязвимостей на страницу