MEDIUM5.3
GHSA-mv4h-qm24-x4gh
Converse.js Exposure of Sensitive Information
Quick fix
GHSA-mv4h-qm24-x4gh — jcbrand/converse.js: upgrade to the fixed version with the command below.
composer require jcbrand/converse.js:^3.3.3Details
Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting software components do not necessarily make that happen.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/jcbrand/converse.js
Introduced in:
0Fixed in: 3.3.3Fix
composer require jcbrand/converse.js:^3.3.3