Intel

AIKIDO-2024-10440

@powersync/web is vulnerable to Cleartext Transmission of Sensitive Information

Cleartext Transmission of Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 13, 2024

30

Low Risk

This Affects:

js@powersync/web
0.5.1 - 1.10.1
Fixed in 1.10.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package fail to protect against the use of insecure connections when logging in with the token connector. This vulnerability exposes sensitive data to interception, as attackers could potentially exploit.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@powersync/web is vulnerable to Cleartext Transmission of Sensitive Information in versions 0.5.1 - 1.10.1.

How to fix this

Upgrade the @powersync/web library to the patch version.