VDB
Sign up
MEDIUM4.8

GHSA-v923-w3x8-wh69

Passport vulnerable to session regeneration when a users logs in or out

Quick fix

GHSA-v923-w3x8-wh69 — passport: upgrade to the fixed version with the command below.

npm install passport@0.6.0

Details

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/passport
Introduced in: 0Fixed in: 0.6.0
Fixnpm install passport@0.6.0

References