Junglewise Threat Intelligence

CVE-2022-24762: sysend cross-domain information disclosure

CVE-2022-24762 · Severity: low · CVSS 3.1 · Published 2022-03-14

Vendors: npm.

Executive brief

sysend.js is a browser library that enables web pages to communicate across different tabs and windows in the same browser. The library failed to properly validate message origins in cross-domain scenarios, allowing sensitive information sent in messages to be intercepted by other pages in the same browser. While the impact is limited to same-browser attacks, this could lead to exposure of session tokens, personal data, or other confidential information transmitted via the library.

Technical details

The vulnerability is an information disclosure issue (CWE-200, CWE-346) in sysend.js's cross-origin messaging mechanism. The library did not properly validate the origin of incoming messages during cross-domain communication, allowing any page running in the same browser to potentially intercept sensitive data. The attack vector is local (requires running code in the same browser) and does not require authentication or network access. An attacker with access to another tab or window in the same browser can capture messages containing user credentials, tokens, or other sensitive information transmitted through sysend. The vulnerability was fixed in version 1.10.0 by implementing proper origin validation checks.

Affected products

  • jcubic sysend < 1.10.0

Timeline

  • 2022-03-14: disclosed
  • 2022-03-13: patched: Version 1.10.0 released

References