Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
CVE–2022–1650
Vulnerable dependency: eventsource (npm) 1.0.7
Vulnerability details
Description
Exposure of Sensitive Information to an Unauthorized Actor
NVD
GitHub
CVSS details - 9.3
References
Exposure of Sensitive Information in eventsource · CVE-2022-1650 · GitHub Advisory Database · GitHub
THIRD PARTY
fix: strip sensitive headers on redirect to different origin · EventSource/eventsource@10ee0c4 · GitHub
Exposure of Sensitive Information to an Unauthorized Actor vulnerability found in eventsource
eventsource/eventsource.js at 82e034389bd2c08d532c63172b8e858c5b185338 · EventSource/eventsource · GitHub
fix: strip sensitive headers on redirect to different origin · EventSource/eventsource@f9f6416 · GitHub
Who to contact for security issues · Issue #244 · EventSource/eventsource · GitHub
GitHub - EventSource/eventsource: EventSource client for Node.js and Browser (polyfill)
Comparing EventSource:HEAD...sampaguitas:master · EventSource/eventsource · GitHub
Who to contact for security issues · Issue #244 · EventSource/eventsource · GitHub
Fix: strip sensitive headers on redirect to different origin by rexxars · Pull Request #273 · EventSource/eventsource · GitHub
Related information
📌 Remember! Check the changes to ensure they don't introduce any breaking changes.
📚 Read more about the CVE