Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS00dnZnLXg4NnAtbXZxY80ymA

Leaking of user information on Cross-Domain communication in sysend

Impact

Users that use Cross-Origin communication and send sensitive information make it possible for this data to be intercepted.
This is not a big impact because it happens only on the same browser.

Patches

It has been patched in version 1.10.0

Workarounds

The only workaround is to not send sensitive information with sysend messages.

Permalink: https://github.com/advisories/GHSA-4vvg-x86p-mvqc
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00dnZnLXg4NnAtbXZxY80ymA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 2 years ago
Updated: about 1 year ago


CVSS Score: 6.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Identifiers: GHSA-4vvg-x86p-mvqc, CVE-2022-24762
References: Repository: https://github.com/jcubic/sysend.js
Blast Radius: 7.6

Affected Packages

npm:sysend
Dependent packages: 2
Dependent repositories: 15
Downloads: 15,585 last month
Affected Version Ranges: < 1.10.0
Fixed in: 1.10.0
All affected versions: 1.0.0, 1.0.1, 1.1.0, 1.2.0, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.4.0, 1.5.0, 1.6.0, 1.6.1, 1.6.2, 1.7.0, 1.7.1, 1.8.0, 1.8.1, 1.9.0
All unaffected versions: 1.10.0, 1.11.0, 1.11.1, 1.12.1, 1.12.2, 1.12.3, 1.14.0, 1.14.1, 1.14.2, 1.14.3, 1.15.0, 1.16.0, 1.16.1, 1.16.2, 1.16.3, 1.17.0, 1.17.1, 1.17.2, 1.17.3, 1.17.4