Junglewise Threat Intelligence

CVE-2024-37162: zsa generation of error message containing sensitive information

CVE-2024-37162 · Severity: low · CVSS 3.1 · Published 2024-06-06

Vendors: npm.

Executive brief

zsa is a TypeScript/JavaScript library for building type-safe server actions. In production mode, the library exposes detailed parse error stack traces to clients, potentially revealing sensitive server information such as usernames and file paths. This information disclosure could enable attackers to better understand the server architecture and plan targeted attacks.

Technical details

The vulnerability is a classic information disclosure (CWE-209) in which zsa transmits server-side parsing error stacks to clients in production build mode. The root cause is insufficient filtering of error output before sending responses to the client. An attacker can trigger parsing errors by sending crafted requests and receive detailed stack traces that expose system information. No authentication or special preconditions are required—any network-accessible instance is vulnerable. The vulnerability is fixed in version 0.3.3; users must upgrade to eliminate the risk of information leakage.

Affected products

  • zsa zsa < 0.3.3

Timeline

  • 2024-06-06: disclosed
  • 2024-06-06: patched: Fixed in version 0.3.3

References