Skip to content

Tovy 8/27/22

High
trulyWHOOOP published GHSA-29f5-6f45-wfhq Aug 27, 2022

Package

index.js (node.js)

Affected versions

< 0.7.72

Patched versions

0.7.72

Description

Impact

This is a high secruity risk due to the nature of it exposing 2fa
The passwords are hashed making it very very hard for them to actually login to your account though they could use your 2fa if they had the password

Patches

This has been patched in versions 0.7.72 above

Workarounds

No

For more information

If you have any questions or comments about this advisory:

Join our [discord](https://tovyblox.xyz/discord)

Severity

High

CVE ID

No known CVE

Weaknesses