CVE-2022-1650

Description

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

Risk Information

Base Score
9.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
EPSS Score
Exploitation Probability
1.141

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.1Windows
EventSource client for Node.js and Browser (polyfill) (USN-6082-1) node-eventsource_0.1.6-1_all.debLinux
EventSource client for Node.js and Browser (polyfill) (USN-6082-1) node-eventsource_1.1.0+~1.1.8-1ubuntu0.1_all.debLinux
EventSource client for Node.js and Browser (polyfill) (USN-6082-1) node-eventsource_0.2.1-1+deb10u1build0.18.04.1_all.debLinux
EventSource client for Node.js and Browser (polyfill) (USN-6082-1) node-eventsource_0.2.1-1+deb10u1build0.20.04.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234