CVE-2018-6591
Last modified
CVE-2018-6591 is a vulnerability of currently unknown severity. Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting software components do not necessarily make that happen.. EPSS estimates a 1.12% chance of exploitation in the next 30 days.
Description
Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting software components do not necessarily make that happen.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Conversejs | Converse.Js | <= 3.3 |
References
- https://gultsch.de/converse_bookmarks.htmlMitigation, Third Party Advisory
- https://gultsch.de/converse_bookmarks.htmlMitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-6591?
How severe is CVE-2018-6591?
How do I fix CVE-2018-6591?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-6585SQL Injection exists in the JTicketing 2.0.16 component for …
- CVE-2018-6586CA API Developer Portal 3.5 up to and including 3.5 CR6 has …6.1
- CVE-2018-6587CA API Developer Portal 3.5 up to and including 3.5 CR6 has …6.1
- CVE-2018-6588CA API Developer Portal 3.5 up to and including 3.5 CR5 has …6.1
- CVE-2018-6589CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x p…7.5
- CVE-2018-6590CA API Developer Portal 4.x, prior to v4.2.5.3 and v4.2.7.1,…6.1
- CVE-2018-6592Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow …
- CVE-2018-6593An issue was discovered in MalwareFox AntiMalware 2.74.0.150…
- CVE-2018-6594lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 ge…
- CVE-2018-6596webhooks/base.py in Anymail (aka django-anymail) before 1.2.…
- CVE-2018-6597The Alcatel A30 device with a build fingerprint of TCL/5046G…
- CVE-2018-6598An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:…
Are you affected by CVE-2018-6591?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
