PT-2018-17655 · Unknown · Inverse.Js+1

Daniel Gultsch

·

Published

2018-02-19

·

Updated

2022-05-14

·

CVE-2018-6591

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Converse.js and Inverse.js versions prior to 3.4
Description The issue allows remote attackers to obtain sensitive information due to the difficulty in determining whether the safe publication of private data was configured or intended. This could lead to the exposure of private data, such as chatroom bookmarks, which users might expect to be private.
Recommendations For Converse.js and Inverse.js versions prior to 3.4, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-6591
GHSA-MV4H-QM24-X4GH

Affected Products

Converse.Js
Inverse.Js