Skip to content

CVE-2022-1650 @ Npm-eventsource-0.1.6 #173

@cx-svetlana-shur

Description

@cx-svetlana-shur

Vulnerable Package issue exists @ Npm-eventsource-0.1.6 in branch main

Exposure of Sensitive Information to an Unauthorized Actor in eventsource before 1.1.1 and 2.0.x before 2.0.2.

Namespace: Svetlana-github
Repository: test
Repository Url: https://github.com/Svetlana-github/test
CxAST-Project: Svetlana-github/test
CxAST platform scan: 8821ba41-d324-41fa-8053-d13dfc156a43
Branch: main
Application: test
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-200


Addition Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: HIGH
Availability impact: NONE
Remediation Upgrade Recommendation: 1.1.1


References
Advisory
Commit
Disclosure

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions