First published: Thu May 12 2022(Updated: )
A flaw was found in the EventSource NPM Package. The description from the source states the following message: "Exposure of Sensitive Information to an Unauthorized Actor." This flaw allows an attacker to steal the user's credentials and then use the credentials to access the legitimate website.
Credit: security@huntr.dev security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-dotnet31-dotnet | <0:3.1.422-1.el7_9 | 0:3.1.422-1.el7_9 |
redhat/rh-dotnet60-dotnet | <0:6.0.107-1.el7_9 | 0:6.0.107-1.el7_9 |
redhat/dotnet6.0 | <0:6.0.107-1.el8_6 | 0:6.0.107-1.el8_6 |
redhat/dotnet3.1 | <0:3.1.422-1.el8_6 | 0:3.1.422-1.el8_6 |
redhat/dotnet6.0 | <0:6.0.107-1.el9_0 | 0:6.0.107-1.el9_0 |
npm/eventsource | >=2.0.0<2.0.2 | 2.0.2 |
npm/eventsource | <1.1.1 | 1.1.1 |
IBM Planning Analytics | <=2.1 | |
IBM Planning Analytics | <=2.0 | |
redhat/eventsource | <2.0.2 | 2.0.2 |
eventsource eventsource | <1.1.1 | |
eventsource eventsource | >=2.0.0<2.0.2 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-1650 is categorized as a high severity vulnerability due to the risk of credential theft.
To remediate CVE-2022-1650, upgrade to the patched versions of the affected packages, specifically eventsource version 2.0.2 or later.
CVE-2022-1650 affects the eventsource NPM package and various Red Hat Dotnet packages including rh-dotnet31-dotnet and rh-dotnet60-dotnet.
CVE-2022-1650 allows attackers to expose sensitive information, leading to potential credential theft for unauthorized access.
Yes, exploitation of CVE-2022-1650 can occur through weaknesses in the eventsource NPM package that allow attackers to steal user credentials.