DSA Study Hub is an interactive educational web application. Prior to commit d527fba, the user authentication system in server/routes/auth.js was found to be vulnerable to Insufficiently Protected Credentials. Authentication tokens (JWTs) were stored in HTTP cookies without cryptographic protection of the payload. This issue has been patched via commit d527fba.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toxicbishop
Toxicbishop dsa-with-tsx |
|
| Vendors & Products |
Toxicbishop
Toxicbishop dsa-with-tsx |
Sat, 07 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DSA Study Hub is an interactive educational web application. Prior to commit d527fba, the user authentication system in server/routes/auth.js was found to be vulnerable to Insufficiently Protected Credentials. Authentication tokens (JWTs) were stored in HTTP cookies without cryptographic protection of the payload. This issue has been patched via commit d527fba. | |
| Title | dsa-hub-server: Clear-Text Storage of Sensitive Data | |
| Weaknesses | CWE-311 CWE-522 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-07T16:06:51.072Z
Updated: 2026-03-07T16:06:51.072Z
Reserved: 2026-03-02T21:43:19.927Z
Link: CVE-2026-28678
No data.
Status : Awaiting Analysis
Published: 2026-03-07T16:15:54.010
Modified: 2026-03-09T13:35:07.393
Link: CVE-2026-28678
No data.