GHSA-4vvg-x86p-mvqc

Suggest an improvement
Source
https://github.com/advisories/GHSA-4vvg-x86p-mvqc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-4vvg-x86p-mvqc/GHSA-4vvg-x86p-mvqc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4vvg-x86p-mvqc
Aliases
Published
2022-03-14T22:43:23Z
Modified
2023-11-08T04:08:35Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Leaking of user information on Cross-Domain communication in sysend
Details

Impact

Users that use Cross-Origin communication and send sensitive information make it possible for this data to be intercepted. This is not a big impact because it happens only on the same browser.

Patches

It has been patched in version 1.10.0

Workarounds

The only workaround is to not send sensitive information with sysend messages.

Database specific
{
    "cwe_ids":  [
        "CWE-200",
        "CWE-346"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-03-14T22:43:23Z",
    "nvd_published_at":  "2022-03-14T23:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / sysend

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.10.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-4vvg-x86p-mvqc/GHSA-4vvg-x86p-mvqc.json"