Description
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
Remediation
References
https://github.com/jaredhanson/passport/commit/7e9b9cf4d7be02428e963fc729496a45baeea608
https://github.com/jaredhanson/passport/pull/900
https://snyk.io/vuln/SNYK-JS-PASSPORT-2840631
Related Vulnerabilities
CVE-2020-7602 Vulnerability in npm package node-prompt-here
CVE-2022-25967 Vulnerability in npm package eta
CVE-2020-10650 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-41038 Vulnerability in npm package @theia/plugin-ext
CVE-2013-2254 Vulnerability in maven package org.apache.sling:org.apache.sling.servlets.post