Open mend-bolt-for-github[bot] opened 2 years ago
Simple, unobtrusive authentication for Node.js.
Library home page: https://registry.npmjs.org/passport/-/passport-0.4.1.tgz
Path to dependency file: /components/discovery/yarn.lock
Path to vulnerable library: /components/discovery/yarn.lock
Dependency Hierarchy: - :x: **passport-0.4.1.tgz** (Vulnerable Library)
Found in base branch: main
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
Publish Date: 2022-07-01
URL: CVE-2022-25896
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: High - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25896
Release Date: 2022-07-01
Fix Resolution: 0.6.0
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
Vulnerable Library - passport-0.4.1.tgz
Simple, unobtrusive authentication for Node.js.
Library home page: https://registry.npmjs.org/passport/-/passport-0.4.1.tgz
Path to dependency file: /components/discovery/yarn.lock
Path to vulnerable library: /components/discovery/yarn.lock
Vulnerabilities
Details
CVE-2022-25896
### Vulnerable Library - passport-0.4.1.tgzSimple, unobtrusive authentication for Node.js.
Library home page: https://registry.npmjs.org/passport/-/passport-0.4.1.tgz
Path to dependency file: /components/discovery/yarn.lock
Path to vulnerable library: /components/discovery/yarn.lock
Dependency Hierarchy: - :x: **passport-0.4.1.tgz** (Vulnerable Library)
Found in base branch: main
### Vulnerability DetailsThis affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
Publish Date: 2022-07-01
URL: CVE-2022-25896
### CVSS 3 Score Details (4.8)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: High - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25896
Release Date: 2022-07-01
Fix Resolution: 0.6.0
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)