CVE-2022-1650
Published: 12 May 2022
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository eventsource/eventsource prior to v2.0.2.
Priority
Status
Package | Release | Status |
---|---|---|
node-eventsource Launchpad, Ubuntu, Debian |
bionic |
Released
(0.2.1-1+deb10u1build0.18.04.1)
|
focal |
Released
(0.2.1-1+deb10u1build0.20.04.1)
|
|
impish |
Ignored
(reached end-of-life)
|
|
jammy |
Released
(1.1.0+~1.1.8-1ubuntu0.1)
|
|
kinetic |
Not vulnerable
(2.0.2+~1.1.8-1)
|
|
lunar |
Not vulnerable
(2.0.2+~1.1.8-1)
|
|
upstream |
Released
(2.0.2+~1.1.8-1)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.3 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Changed |
Confidentiality | High |
Integrity impact | High |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1650
- https://huntr.dev/bounties/dc9e467f-be5d-4945-867d-1044d27e9b8e/
- https://github.com/eventsource/eventsource/commit/10ee0c4881a6ba2fe65ec18ed195ac35889583c4 (v2.0.2)
- https://huntr.dev/bounties/dc9e467f-be5d-4945-867d-1044d27e9b8e
- https://github.com/eventsource/eventsource/commit/10ee0c4881a6ba2fe65ec18ed195ac35889583c4
- https://ubuntu.com/security/notices/USN-6082-1
- NVD
- Launchpad
- Debian