logo

CVE-2018-6591 jcbrand/converse.js

Package

Manager: composer
Name: jcbrand/converse.js
Vulnerable Version: >=0 <3.3.3

Severity

Level: Medium

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00265 pctl0.49755

Details

Converse.js Exposure of Sensitive Information Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting software components do not necessarily make that happen.

Metadata

Created: 2022-05-14T03:12:35Z
Modified: 2023-10-06T17:38:05Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mv4h-qm24-x4gh/GHSA-mv4h-qm24-x4gh.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-mv4h-qm24-x4gh
Finding: F017
Auto approve: 1