Description
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
Remediation
References
https://github.com/jaredhanson/passport/commit/7e9b9cf4d7be02428e963fc729496a45baeea608
https://github.com/jaredhanson/passport/pull/900
https://snyk.io/vuln/SNYK-JS-PASSPORT-2840631
Related Vulnerabilities
CVE-2022-2390 Vulnerability in maven package com.google.android.gms:play-services-basement
CVE-2023-26132 Vulnerability in npm package dottie
CVE-2022-24723 Vulnerability in npm package urijs
CVE-2019-10759 Vulnerability in npm package safer-eval
CVE-2022-41936 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rest-server