OSV 1.4.0 · github-reviewed · 修改于 2021-09-01 04:56
发布时间
2019-05-31 01:26
GitHub 审查时间
2019-05-31 01:25
NVD 发布时间
—
源文件
advisories/github-reviewed/2019/05/GHSA-27v7-qhfv-rqq8/GHSA-27v7-qhfv-rqq8.json
All versions of web3 are vulnerable to Insecure Credential Storage. The package stores encrypted wallets in local storage and requires a password to load the wallet. Once the wallet is loaded, the private key is accessible via LocalStorage. Exploiting this vulnerability likely requires a Cross-Site Scripting vulnerability to access the private key.
No fix is currently available. Consider using an alternative module until a fix is made available.