Количество 2
Количество 2
CVE-2025-60794
Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, potentially leading to session hijacking.
GHSA-62vx-hpcr-m9ch
@perfood/couch-auth may expose session tokens, passwords
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-60794 Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, potentially leading to session hijacking. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-62vx-hpcr-m9ch @perfood/couch-auth may expose session tokens, passwords | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу