GHSA-27v7-qhfv-rqq8
Dashboard / Vulnerabilities / GHSA-27v7-qhfv-rqq8
GHSA-27v7-qhfv-rqq8
Summary: Insecure Credential Storage in web3
Details: All versions of `web3` are vulnerable to Insecure Credential Storage. The package stores encrypted wallets in local storage and requires a password to load the wallet. Once the wallet is loaded, the private key is accessible via LocalStorage. Exploiting this vulnerability likely requires a Cross-Site Scripting vulnerability to access the private key. ## Recommendation No fix is currently available. Consider using an alternative module until a fix is made available.
References: https://github.com/ethereum/web3.js/issues/2739, https://github.com/ethereum/web3.js, https://snyk.io/vuln/SNYK-JS-WEB3-174533, https://www.npmjs.com/advisories/877
Affected packages
Package
Name: web3
Purl: pkg:npm/web3
Affected ranges
Type: SEMVER
Events:
