html inputs of type password recorded in plaintext when converted to text inputs
- Severity:
- Medium
Description
Highlight may record passwords on customer deployments when a password html input is switched to type="text"
via a javascript “Show Password” button. This differs from the expected behavior which always obfuscates type="password"
inputs.
Recommendation
Update the highlight.run
package to the latest compatible version. Followings are version details:
- Affected version(s): < 6.0.0
- Patched version(s): 6.0.0
References
Related Issues
- Regular Expression Denial of Service (ReDoS) in lodash (GHSA-x5rq-j2xg-h7qm) 3 - CVE-2019-1010266
- Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query - CVE-2025-31125
- Prototype pollution vulnerability found in Mermaid's bundled version of DOMPurify - Vulnerability
- thlorenz browserify-shim vulnerable to prototype pollution (GHSA-r737-347m-wqc7) - CVE-2022-37621
- Tags:
- npm
- highlight.run
Anything's wrong? Let us know Last updated on November 08, 2023