Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS00dnZnLXg4NnAtbXZxY80ymA
Leaking of user information on Cross-Domain communication in sysend
Impact
Users that use Cross-Origin communication and send sensitive information make it possible for this data to be intercepted.
This is not a big impact because it happens only on the same browser.
Patches
It has been patched in version 1.10.0
Workarounds
The only workaround is to not send sensitive information with sysend messages.
Permalink: https://github.com/advisories/GHSA-4vvg-x86p-mvqcJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00dnZnLXg4NnAtbXZxY80ymA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 2 years ago
Updated: about 1 year ago
CVSS Score: 6.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Identifiers: GHSA-4vvg-x86p-mvqc, CVE-2022-24762
References:
- https://github.com/jcubic/sysend.js/security/advisories/GHSA-4vvg-x86p-mvqc
- https://github.com/jcubic/sysend.js/issues/33
- https://github.com/jcubic/sysend.js/commit/a24f4b776fb18191ae0f7e3d90c2c7bec459431a
- https://nvd.nist.gov/vuln/detail/CVE-2022-24762
- https://github.com/jcubic/sysend.js/releases/tag/1.10.0
- https://github.com/advisories/GHSA-4vvg-x86p-mvqc
Blast Radius: 7.6
Affected Packages
npm:sysend
Dependent packages: 2Dependent repositories: 15
Downloads: 15,585 last month
Affected Version Ranges: < 1.10.0
Fixed in: 1.10.0
All affected versions: 1.0.0, 1.0.1, 1.1.0, 1.2.0, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.4.0, 1.5.0, 1.6.0, 1.6.1, 1.6.2, 1.7.0, 1.7.1, 1.8.0, 1.8.1, 1.9.0
All unaffected versions: 1.10.0, 1.11.0, 1.11.1, 1.12.1, 1.12.2, 1.12.3, 1.14.0, 1.14.1, 1.14.2, 1.14.3, 1.15.0, 1.16.0, 1.16.1, 1.16.2, 1.16.3, 1.17.0, 1.17.1, 1.17.2, 1.17.3, 1.17.4