Intel

AIKIDO-2024-10040

nestjs-cls is vulnerable to Sensitive Information in Resource Not Removed Before Reuse

Sensitive Information in Resource Not Removed Before Reuse Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 22, 2024

22

Low Risk

This Affects:

JSnestjs-cls
3.5.1 - 4.2.0
Fixed in 4.2.1
Are you affected? Scan for Free

TL;DR

The affected versions may lead to information leakage between different calls. Unless all properties in the store are overridden before the program flow reaches business logic, data from a previous call could be used in the current call. The risk is low, as the vulnerability has not been exploited, and its impact largely depends on how the vulnerable code is used.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

nestjs-cls is vulnerable to Sensitive Information in Resource Not Removed Before Reuse in versions 3.5.1 - 4.2.0.

How to fix this

Upgrade the nestjs-cls library to the patch version.