Vulnerability Name: | CVE-2022-1650 (CCN-226482) | ||||||||||||||||||
Assigned: | 2022-02-06 | ||||||||||||||||||
Published: | 2022-02-06 | ||||||||||||||||||
Updated: | 2023-08-02 | ||||||||||||||||||
Summary: | |||||||||||||||||||
CVSS v3 Severity: | 8.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N) 7.3 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C)
8.4 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:P/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
| ||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-1650 Source: XF Type: UNKNOWN eventsource-cve20221650-info-disc(226482) Source: CCN Type: EventSource GIT Repository fix: strip sensitive headers on redirect to different origin Source: security@huntr.dev Type: Patch, Third Party Advisory security@huntr.dev Source: security@huntr.dev Type: Exploit, Issue Tracking, Patch, Third Party Advisory security@huntr.dev Source: CCN Type: huntr Web site Exposure of Sensitive Information to an Unauthorized Actor in eventsource/eventsource Source: security@huntr.dev Type: Mailing List, Third Party Advisory security@huntr.dev Source: CCN Type: SNYK-JS-EVENTSOURCE-2823375 Information Exposure Source: CCN Type: IBM Security Bulletin 6832944 (Business Automation Manager Open Editions) Multiple security vulnerabilities are addressed with IBM Business Automation Manager Open Editions 8.0.1 Source: CCN Type: IBM Security Bulletin 6991595 (Edge Application Manager) Open Source Dependency Vulnerability | ||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |