{"id":"GHSA-4vvg-x86p-mvqc","summary":"Leaking of user information on Cross-Domain communication in sysend","details":"### Impact\nUsers that use Cross-Origin communication and send sensitive information make it possible for this data to be intercepted.\nThis is not a big impact because it happens only on the same browser.\n\n### Patches\nIt has been patched in version 1.10.0\n\n### Workarounds\nThe only workaround is to not send sensitive information with sysend messages.\n\n","aliases":["CVE-2022-24762"],"modified":"2023-11-08T04:08:35.613992Z","published":"2022-03-14T22:43:23Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-03-14T22:43:23Z","nvd_published_at":"2022-03-14T23:15:00Z","cwe_ids":["CWE-200","CWE-346"]},"references":[{"type":"WEB","url":"https://github.com/jcubic/sysend.js/security/advisories/GHSA-4vvg-x86p-mvqc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24762"},{"type":"WEB","url":"https://github.com/jcubic/sysend.js/issues/33"},{"type":"WEB","url":"https://github.com/jcubic/sysend.js/commit/a24f4b776fb18191ae0f7e3d90c2c7bec459431a"},{"type":"WEB","url":"https://github.com/jcubic/sysend.js"},{"type":"WEB","url":"https://github.com/jcubic/sysend.js/releases/tag/1.10.0"}],"affected":[{"package":{"name":"sysend","ecosystem":"npm","purl":"pkg:npm/sysend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.10.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-4vvg-x86p-mvqc/GHSA-4vvg-x86p-mvqc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}