Information disclosure in EventSource - CVE-2022-1650

 

Information disclosure in EventSource - CVE-2022-1650

Published: May 30, 2022


Vulnerability identifier: #VU63777
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1650
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

EventSource
SockJS Client
Migration Toolkit for Containers
IBM Edge Application Manager
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Storage Fusion Data Foundation
IBM Business Automation Manager Open Editions
Storage Ceph
rh-dotnet60-dotnet (Red Hat package)
dotnet6.0 (Red Hat package)
node-eventsource (Ubuntu package)
dotnet-targeting-pack-6.0
aspnetcore-runtime-6.0
aspnetcore-targeting-pack-6.0
dotnet-runtime-6.0
dotnet-apphost-pack-6.0
dotnet-host
dotnet-hostfxr-6.0
dotnet-templates-6.0
dotnet-sdk-6.0-source-built-artifacts
dotnet-sdk-6.0
dotnet
netstandard-targeting-pack-2.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Fuse
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Ubuntu
Planning Analytics Local
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat Ceph Storage

How to mitigate CVE-2022-1650

Install updates from vendor's website.

EventSource - update to 2.0.2
SockJS Client - update to 1.6.1
Migration Toolkit for Containers - update to 1.7.4
OpenShift Service Mesh - update to 2.1.3
Storage Fusion Data Foundation - update to 4.11.0
rh-dotnet60-dotnet (Red Hat package) - update to 6.0.107-1.el7_9
dotnet6.0 (Red Hat package) - addressed in versions 6.0.107-1.el8_6, 6.0.107-1.el9_0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
Fuse - update to 7.10.2-P1
IBM Business Automation Manager Open Editions - update to 8.0.1
node-eventsource (Ubuntu package) - addressed in versions Ubuntu Pro, 0.2.1-1+deb10u1build0.18.04.1, 0.2.1-1+deb10u1build0.20.04.1, 1.1.0+~1.1.8-1ubuntu0.1
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
dotnet-targeting-pack-6.0 - update to 6.0.7-1.0.1
aspnetcore-runtime-6.0 - update to 6.0.7-1.0.1
aspnetcore-targeting-pack-6.0 - update to 6.0.7-1.0.1
dotnet-runtime-6.0 - update to 6.0.7-1.0.1
dotnet-apphost-pack-6.0 - update to 6.0.7-1.0.1
dotnet-host - update to 6.0.7-1.0.1
dotnet-hostfxr-6.0 - update to 6.0.7-1.0.1
dotnet-templates-6.0 - update to 6.0.107-1.0.1
dotnet-sdk-6.0-source-built-artifacts - update to 6.0.107-1.0.1
dotnet-sdk-6.0 - update to 6.0.107-1.0.1
dotnet - update to 6.0.107-1.0.1
netstandard-targeting-pack-2.1 - update to 6.0.107-1.0.1
Storage Ceph - update to 6.1
Red Hat Ceph Storage - update to 6.1

External References

Related Security Bulletins