Description
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
Remediation
References
https://github.com/jaredhanson/passport/pull/900
https://snyk.io/vuln/SNYK-JS-PASSPORT-2840631
https://github.com/jaredhanson/passport/commit/7e9b9cf4d7be02428e963fc729496a45baeea608
Related Vulnerabilities
CVE-2017-5617 Vulnerability in maven package com.kitfox.svg:svg-salamander
CVE-2020-28438 Vulnerability in npm package deferred-exec
CVE-2021-33360 Vulnerability in npm package @stoqey/gnuplot
CVE-2020-1956 Vulnerability in maven package org.apache.kylin:kylin-core-common
CVE-2022-31172 Vulnerability in npm package @openzeppelin/contracts-upgradeable