Further research determined the issue is not a vulnerability.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Update the application to commit d527fba3b3c15f185b9d1e730322dff9248391e4, which fixes the cookie storage logic.
- Configure authentication cookies with the HTTPOnly and Secure flags and enforce HTTPS for all connections.
- Ensure that JSON Web Tokens are signed with a strong algorithm and that the payload is encrypted or contains minimal sensitive data.
Generated by OpenCVE AI on April 17, 2026 at 12:09 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Tue, 30 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | dsa-hub-server: Clear-Text Storage of Sensitive Data | |
| Metrics |
ssvc
|
Tue, 30 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DSA Study Hub is an interactive educational web application. Prior to commit d527fba, the user authentication system in server/routes/auth.js was found to be vulnerable to Insufficiently Protected Credentials. Authentication tokens (JWTs) were stored in HTTP cookies without cryptographic protection of the payload. This issue has been patched via commit d527fba. | Further research determined the issue is not a vulnerability. |
Wed, 11 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toxicbishop dsa Study Hub
|
|
| CPEs | cpe:2.3:a:toxicbishop:dsa_study_hub:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Toxicbishop dsa Study Hub
|
Mon, 09 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toxicbishop
Toxicbishop dsa-with-tsx |
|
| Vendors & Products |
Toxicbishop
Toxicbishop dsa-with-tsx |
Sat, 07 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DSA Study Hub is an interactive educational web application. Prior to commit d527fba, the user authentication system in server/routes/auth.js was found to be vulnerable to Insufficiently Protected Credentials. Authentication tokens (JWTs) were stored in HTTP cookies without cryptographic protection of the payload. This issue has been patched via commit d527fba. | |
| Title | dsa-hub-server: Clear-Text Storage of Sensitive Data | |
| Weaknesses | CWE-311 CWE-522 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: GitHub_M
Published:
Updated: 2026-06-30T18:36:40.195Z
Reserved: 2026-03-02T21:43:19.927Z
Link: CVE-2026-28678
Updated:
Status : Rejected
Published: 2026-03-07T16:15:54.010
Modified: 2026-06-30T19:16:28.153
Link: CVE-2026-28678
No data.
OpenCVE Enrichment
Updated: 2026-04-17T12:15:18Z
No weakness.