CVE-2022-1650
published 2022-05-12CVE-2022-1650: Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.
PriorityP339critical9.3CVSS 3.1
AVNACLPRNUIRSCCHIHAN
EPSS
1.85%
77.0th percentile
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | node-eventsource | < node-eventsource 2.0.2+~1.1.8-1 (bookworm) | node-eventsource 2.0.2+~1.1.8-1 (bookworm) |
| eventsource | eventsource | < 1.1.1 | 1.1.1 |
| eventsource | eventsource | >= 0 < 1.1.1 | 1.1.1 |
| eventsource | eventsource | >= 2.0.0 < 2.0.2 | 2.0.2 |
| eventsource | eventsource | >= 2.0.0 < 2.0.2 | 2.0.2 |
| eventsource | eventsource_eventsource | >= unspecified < v2.0.2 | v2.0.2 |
| eventsource | eventsource_eventsource | unspecified – v1.1.0 | — |
| eventsource | eventsource_eventsource | >= v2.0.0 < unspecified | unspecified |
CVSS provenance
nvdv3.19.3CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv9.3CRITICAL
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
EventSource vulnerability
vendor_ubuntu·2023-05-17
CVE-2022-1650 EventSource vulnerability
Title: EventSource vulnerability
Summary: EventSource could leak sensitive information if it opened a specially crafted
input file.
It was discovered that EventSource incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to obtain
sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
eventsource: Exposure of Sensitive Information
vendor_redhat·2022-05-12·CVSS 8.1
CVE-2022-1650 [HIGH] CWE-359 eventsource: Exposure of Sensitive Information
eventsource: Exposure of Sensitive Information
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.
A flaw was found in the EventSource NPM Package. The description from the source states the following message: "Exposure of Sensitive Information to an Unauthorized Actor." This flaw allows an attacker to steal the user's credentials and then use the credentials to access the legitimate website.
Package: migration-toolkit-virtualization/mtv-ui-rhel8 (Migration Toolkit for Virtualization) - Affected
Package: odo (OpenShift Developer Tools and Services) - Affected
Package: servicemesh-prometheus (OpenShift Service Mesh 2.0) - Affected
Package: servicemesh-grafana (OpenShift Service Mesh 2.1) - Affected
Package
Debian
CVE-2022-1650: node-eventsource - Improper Removal of Sensitive Information Before Storage or Transfer in GitHub r...
vendor_debian·2022·CVSS 8.1
CVE-2022-1650 [HIGH] CVE-2022-1650: node-eventsource - Improper Removal of Sensitive Information Before Storage or Transfer in GitHub r...
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.
Scope: local
bookworm: resolved (fixed in 2.0.2+~1.1.8-1)
bullseye: resolved (fixed in 1.0.7-1+deb11u1)
forky: resolved (fixed in 2.0.2+~1.1.8-1)
sid: resolved (fixed in 2.0.2+~1.1.8-1)
trixie: resolved (fixed in 2.0.2+~1.1.8-1)
GHSA
Exposure of Sensitive Information in eventsource
ghsa·2022-05-13
CVE-2022-1650 [CRITICAL] CWE-200 Exposure of Sensitive Information in eventsource
Exposure of Sensitive Information in eventsource
When fetching an url with a link to an external site (Redirect), the users Cookies & Autorisation headers are leaked to the third party application. According to the same-origin-policy, the header should be "sanitized."
OSV
Exposure of Sensitive Information in eventsource
osv·2022-05-13
CVE-2022-1650 [CRITICAL] Exposure of Sensitive Information in eventsource
Exposure of Sensitive Information in eventsource
When fetching an url with a link to an external site (Redirect), the users Cookies & Autorisation headers are leaked to the third party application. According to the same-origin-policy, the header should be "sanitized."
OSV
CVE-2022-1650: Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2
osv·2022-05-12·CVSS 9.3
CVE-2022-1650 [CRITICAL] CVE-2022-1650: Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/eventsource/eventsource/commit/10ee0c4881a6ba2fe65ec18ed195ac35889583c4https://huntr.dev/bounties/dc9e467f-be5d-4945-867d-1044d27e9b8ehttps://lists.debian.org/debian-lts-announce/2022/12/msg00021.htmlhttps://github.com/eventsource/eventsource/commit/10ee0c4881a6ba2fe65ec18ed195ac35889583c4https://huntr.dev/bounties/dc9e467f-be5d-4945-867d-1044d27e9b8ehttps://lists.debian.org/debian-lts-announce/2022/12/msg00021.html
2022-05-12
Published