Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
Link | Tags |
---|---|
https://huntr.dev/bounties/dc9e467f-be5d-4945-867d-1044d27e9b8e | issue tracking patch exploit third party advisory |
https://github.com/eventsource/eventsource/commit/10ee0c4881a6ba2fe65ec18ed195ac35889583c4 | third party advisory patch |
https://lists.debian.org/debian-lts-announce/2022/12/msg00021.html | third party advisory mailing list |