MEDIUM 5.3 Packagist

Converse.js Exposure of Sensitive Information

GHSA-mv4h-qm24-x4gh · CVE-2018-6591

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting software components do not necessarily make that happen.

Ready to move

Start Securing

Free, no credit card | First findings in minutes