VYPR
High severity8.1NVD Advisory· Published May 12, 2022· Updated Jun 17, 2026

CVE-2022-1650

CVE-2022-1650

Description

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
eventsourcenpm
< 1.1.11.1.1
eventsourcenpm
>= 2.0.0, < 2.0.22.0.2

Affected products

4
  • cpe:2.3:a:eventsource:eventsource:*:*:*:*:node.js:*:*:*+ 1 more
    • cpe:2.3:a:eventsource:eventsource:*:*:*:*:node.js:*:*:*range: <1.1.1
    • (no CPE)range: v2.0.0
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 1.1.1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.