CVE-2018-6591 – jcbrand/converse.js
Package
Manager: composer
Name: jcbrand/converse.js
Vulnerable Version: >=0 <3.3.3
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00265 pctl0.49755
Details
Converse.js Exposure of Sensitive Information Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting software components do not necessarily make that happen.
Metadata
Created: 2022-05-14T03:12:35Z
Modified: 2023-10-06T17:38:05Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mv4h-qm24-x4gh/GHSA-mv4h-qm24-x4gh.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-mv4h-qm24-x4gh
Finding: F017
Auto approve: 1