MEDIUM 5.3 Packagist
Converse.js Exposure of Sensitive Information
GHSA-mv4h-qm24-x4gh · CVE-2018-6591
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting software components do not necessarily make that happen.
Ready to move
Start Securing
Free, no credit card | First findings in minutes