{"id":"CVE-2020-11883","aliases":["GHSA-9wxj-37p8-49ff"],"url":"https://o3.security/vulnerability/CVE-2020-11883","summary":"Diavante vue-storefront-api and storefront-api disclose stack trace","details":"In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.","published":"2020-04-17T19:15:14.373Z","modified":"2026-08-27T03:47:47.073613614Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"storefront-api","fixedVersion":"1.0.0-rc3"},{"ecosystem":"npm","name":"vue-storefront-api","fixedVersion":"1.12.0"}],"fix":{"url":"https://github.com/DivanteLtd/storefront-api/pull/59","label":"DivanteLtd/storefront-api#59"},"references":[{"type":"FIX","url":"https://github.com/DivanteLtd/storefront-api/pull/59"},{"type":"FIX","url":"https://github.com/DivanteLtd/vue-storefront-api/pull/431"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:47:47.073613614Z"}}