Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1650

Опубликовано: 12 мая 2022
Источник: redhat
CVSS3: 9.3
EPSS Низкий

Описание

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

A flaw was found in the EventSource NPM Package. The description from the source states the following message: "Exposure of Sensitive Information to an Unauthorized Actor." This flaw allows an attacker to steal the user's credentials and then use the credentials to access the legitimate website.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Affected
OpenShift Developer Tools and ServicesodoAffected
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
OpenShift Service Mesh 2.1servicemesh-grafanaAffected
OpenShift Service Mesh 2.1servicemesh-prometheusAffected
Red Hat 3scale API Management Platform 23scale-systemFix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/kui-web-terminal-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-ui-rhel8Affected
Red Hat A-MQ OnlineeventsourceAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-359
https://bugzilla.redhat.com/show_bug.cgi?id=2085307eventsource: Exposure of Sensitive Information

EPSS

Процентиль: 84%
0.02409
Низкий

9.3 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 3 лет назад

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

CVSS3: 8.1
nvd
около 3 лет назад

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

CVSS3: 8.1
debian
около 3 лет назад

Improper Removal of Sensitive Information Before Storage or Transfer i ...

CVSS3: 9.3
github
около 3 лет назад

Exposure of Sensitive Information in eventsource

CVSS3: 9.3
fstec
около 3 лет назад

Уязвимость библиотеки eventsource/eventsource, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 84%
0.02409
Низкий

9.3 Critical

CVSS3