Description
All users are impacted. The zsa application transfers the parse error stack from the server to the client in production build mode. This can potentially reveal sensitive information about the server environment, such as the machine username and directory paths.
Recommendation
Update the zsa package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.3.3
- Patched version(s): 0.3.3
References
Related Issues
- @sveltejs/kit has unescaped error message included on error page - CVE-2024-53262
- react-native-mmkv Insertion of Sensitive Information into Log File vulnerability - CVE-2024-21668
- Modified package published to npm, containing malware that exfiltrates private key material - CVE-2024-54134
- Improper Removal of Sensitive Information Before Storage or Transfer in Strapi - @strapi/strapi - CVE-2022-30617
You might also like:
- Tags:
- npm
- zsa
Anything's wrong? Let us know Last updated on October 31, 2024


