Information disclosure in EventSource - CVE-2022-1650
Published: May 30, 2022
Vulnerability identifier: #VU63777
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1650
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
EventSource
SockJS Client
Migration Toolkit for Containers
IBM Edge Application Manager
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Storage Fusion Data Foundation
IBM Business Automation Manager Open Editions
Storage Ceph
rh-dotnet60-dotnet (Red Hat package)
dotnet6.0 (Red Hat package)
node-eventsource (Ubuntu package)
dotnet-targeting-pack-6.0
aspnetcore-runtime-6.0
aspnetcore-targeting-pack-6.0
dotnet-runtime-6.0
dotnet-apphost-pack-6.0
dotnet-host
dotnet-hostfxr-6.0
dotnet-templates-6.0
dotnet-sdk-6.0-source-built-artifacts
dotnet-sdk-6.0
dotnet
netstandard-targeting-pack-2.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Fuse
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Ubuntu
Planning Analytics Local
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat Ceph Storage
SockJS Client
Migration Toolkit for Containers
IBM Edge Application Manager
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Storage Fusion Data Foundation
IBM Business Automation Manager Open Editions
Storage Ceph
rh-dotnet60-dotnet (Red Hat package)
dotnet6.0 (Red Hat package)
node-eventsource (Ubuntu package)
dotnet-targeting-pack-6.0
aspnetcore-runtime-6.0
aspnetcore-targeting-pack-6.0
dotnet-runtime-6.0
dotnet-apphost-pack-6.0
dotnet-host
dotnet-hostfxr-6.0
dotnet-templates-6.0
dotnet-sdk-6.0-source-built-artifacts
dotnet-sdk-6.0
dotnet
netstandard-targeting-pack-2.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Fuse
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Ubuntu
Planning Analytics Local
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat Ceph Storage
How to mitigate CVE-2022-1650
Install updates from vendor's website.
EventSource - update to 2.0.2
SockJS Client - update to 1.6.1
Migration Toolkit for Containers - update to 1.7.4
OpenShift Service Mesh - update to 2.1.3
Storage Fusion Data Foundation - update to 4.11.0
rh-dotnet60-dotnet (Red Hat package) - update to 6.0.107-1.el7_9
dotnet6.0 (Red Hat package) - addressed in versions 6.0.107-1.el8_6, 6.0.107-1.el9_0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
Fuse - update to 7.10.2-P1
IBM Business Automation Manager Open Editions - update to 8.0.1
node-eventsource (Ubuntu package) - addressed in versions Ubuntu Pro, 0.2.1-1+deb10u1build0.18.04.1, 0.2.1-1+deb10u1build0.20.04.1, 1.1.0+~1.1.8-1ubuntu0.1
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
dotnet-targeting-pack-6.0 - update to 6.0.7-1.0.1
aspnetcore-runtime-6.0 - update to 6.0.7-1.0.1
aspnetcore-targeting-pack-6.0 - update to 6.0.7-1.0.1
dotnet-runtime-6.0 - update to 6.0.7-1.0.1
dotnet-apphost-pack-6.0 - update to 6.0.7-1.0.1
dotnet-host - update to 6.0.7-1.0.1
dotnet-hostfxr-6.0 - update to 6.0.7-1.0.1
dotnet-templates-6.0 - update to 6.0.107-1.0.1
dotnet-sdk-6.0-source-built-artifacts - update to 6.0.107-1.0.1
dotnet-sdk-6.0 - update to 6.0.107-1.0.1
dotnet - update to 6.0.107-1.0.1
netstandard-targeting-pack-2.1 - update to 6.0.107-1.0.1
Storage Ceph - update to 6.1
Red Hat Ceph Storage - update to 6.1
SockJS Client - update to 1.6.1
Migration Toolkit for Containers - update to 1.7.4
OpenShift Service Mesh - update to 2.1.3
Storage Fusion Data Foundation - update to 4.11.0
rh-dotnet60-dotnet (Red Hat package) - update to 6.0.107-1.el7_9
dotnet6.0 (Red Hat package) - addressed in versions 6.0.107-1.el8_6, 6.0.107-1.el9_0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
Fuse - update to 7.10.2-P1
IBM Business Automation Manager Open Editions - update to 8.0.1
node-eventsource (Ubuntu package) - addressed in versions Ubuntu Pro, 0.2.1-1+deb10u1build0.18.04.1, 0.2.1-1+deb10u1build0.20.04.1, 1.1.0+~1.1.8-1ubuntu0.1
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
dotnet-targeting-pack-6.0 - update to 6.0.7-1.0.1
aspnetcore-runtime-6.0 - update to 6.0.7-1.0.1
aspnetcore-targeting-pack-6.0 - update to 6.0.7-1.0.1
dotnet-runtime-6.0 - update to 6.0.7-1.0.1
dotnet-apphost-pack-6.0 - update to 6.0.7-1.0.1
dotnet-host - update to 6.0.7-1.0.1
dotnet-hostfxr-6.0 - update to 6.0.7-1.0.1
dotnet-templates-6.0 - update to 6.0.107-1.0.1
dotnet-sdk-6.0-source-built-artifacts - update to 6.0.107-1.0.1
dotnet-sdk-6.0 - update to 6.0.107-1.0.1
dotnet - update to 6.0.107-1.0.1
netstandard-targeting-pack-2.1 - update to 6.0.107-1.0.1
Storage Ceph - update to 6.1
Red Hat Ceph Storage - update to 6.1
External References
Related Security Bulletins
- Information disclosure in EventSource
- Information disclosure in sockjs-client
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.1
- Multiple vulnerabilities in Red Hat Fuse
- Red Hat Enterprise Linux 9 update for .NET 6.0
- Red Hat Enterprise Linux 8 update for .NET 6.0
- Red Hat Enterprise Linux 7 update for .NET 6.0
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in Red Hat OpenShift distributed tracing (RHOSDT)
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Information disclosure in IBM Edge Application Manager
- Ubuntu update for node-eventsource
- Multiple vulnerabilities in Red Hat Ceph Storage
- Information disclosure in IBM Ceph Storage
- Multiple vulnerabilities in IBM Planning Analytics
- Anolis OS update for dotnet6.0
- IBM Storage Fusion Data Foundation update for EventSource