Vulnerability CVE-2022-25896


Published: 2022-07-01

Description:
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

 References:
https://github.com/jaredhanson/passport/pull/900
https://snyk.io/vuln/SNYK-JS-PASSPORT-2840631
https://github.com/jaredhanson/passport/commit/7e9b9cf4d7be02428e963fc729496a45baeea608

Copyright 2026, cxsecurity.com

 

Back to Top