PT-2018-17655 · Unknown · Inverse.Js+1
Daniel Gultsch
·
Published
2018-02-19
·
Updated
2022-05-14
·
CVE-2018-6591
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Converse.js and Inverse.js versions prior to 3.4
Description
The issue allows remote attackers to obtain sensitive information due to the difficulty in determining whether the safe publication of private data was configured or intended. This could lead to the exposure of private data, such as chatroom bookmarks, which users might expect to be private.
Recommendations
For Converse.js and Inverse.js versions prior to 3.4, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Converse.Js
Inverse.Js