Skip to content
This repository has been archived by the owner on Mar 1, 2024. It is now read-only.

fixed @ CVE-2022-25896 #35

Merged
merged 1 commit into from
Nov 13, 2022
Merged

fixed @ CVE-2022-25896 #35

merged 1 commit into from
Nov 13, 2022

Conversation

mik-patient
Copy link
Contributor

Signed-off-by: mik-patient 112659896+mik-patient@users.noreply.github.com

Description:
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

CVE-2022-25896
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
GHSA-v923-w3x8-wh69

Signed-off-by: mik-patient <112659896+mik-patient@users.noreply.github.com>
Copy link
Contributor

@lukehb lukehb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@lukehb lukehb merged commit e8cf7f6 into EpicGames:master Nov 13, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants