Skip to content

Leaking of user information on Cross-Domain communication

Moderate
jcubic published GHSA-4vvg-x86p-mvqc Mar 13, 2022

Package

npm sysend (npm)

Affected versions

1.9.0

Patched versions

1.10.0

Description

Impact

Users that use Cross-Origin communication and send sensitive information make it possible for this data to be intercepted.
This is not a big impact because it happens only on the same browser.

Patches

It has been patched in version 1.10.0

Workarounds

The only workaround is to not send sensitive information with sysend messages.

References

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2022-24762

Weaknesses

No CWEs