{"id":"GHSA-27v7-qhfv-rqq8","summary":"Insecure Credential Storage in web3","details":"All versions of `web3` are vulnerable to Insecure Credential Storage. The package stores encrypted wallets in local storage and requires a password to load the wallet. Once the wallet is loaded, the private key is accessible via LocalStorage. Exploiting this vulnerability likely requires a Cross-Site Scripting vulnerability to access the private key.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative module until a fix is made available.","modified":"2021-08-31T20:56:47Z","published":"2019-05-30T17:26:30Z","database_specific":{"github_reviewed_at":"2019-05-30T17:25:54Z","nvd_published_at":null,"cwe_ids":[],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/ethereum/web3.js/issues/2739"},{"type":"PACKAGE","url":"https://github.com/ethereum/web3.js"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-WEB3-174533"},{"type":"WEB","url":"https://www.npmjs.com/advisories/877"}],"affected":[{"package":{"name":"web3","ecosystem":"npm","purl":"pkg:npm/web3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/05/GHSA-27v7-qhfv-rqq8/GHSA-27v7-qhfv-rqq8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}