- 
                Notifications
    
You must be signed in to change notification settings  - Fork 478
 
[GHSA-6h5x-7c5m-7cr7] Exposure of Sensitive Information in eventsource #6045
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[GHSA-6h5x-7c5m-7cr7] Exposure of Sensitive Information in eventsource #6045
Conversation
GHSA-ww66-45gm-65fm GHSA-23j9-36qq-2q2f GHSA-2xjg-x2hw-6m93 GHSA-36rh-jh3r-836q GHSA-3q6c-gxc3-h5vx GHSA-4m92-9mpx-cmcg GHSA-5829-pgch-7qw6 GHSA-9wjv-9mc7-hwv7 GHSA-c48j-9c86-pwjg GHSA-gc7v-hcc9-x542 GHSA-m592-qjjf-q3cf GHSA-q44x-qjgc-xhv8 GHSA-rw5q-23mh-r4c3 GHSA-wg88-6pq6-wm93 GHSA-wqjm-r535-pwhh GHSA-wvhw-4f88-xp55
| 
           Hi @Stonefox36, we see your CVSS suggestion   | 
    
| 
           Sounds good to me 
…On Tue, Aug 26, 2025, 3:48 PM yhidad31 ***@***.***> wrote:
 *yhidad31* left a comment (github/advisory-database#6045)
 <#6045 (comment)>
 Hi @Stonefox36 <https://github.com/Stonefox36>, we see your CVSS
 suggestion CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H. Can you explain
 the rationale for changing Privileges Required and Availability from None
 to High, or link to analysis/supporting references? If you'd like, we can
 run this through the CVSS calculator:
 https://www.first.org/cvss/calculator/3-1 and the score can be updated if
 we agree.
 —
 Reply to this email directly, view it on GitHub
 <#6045 (comment)>,
 or unsubscribe
 <https://github.com/notifications/unsubscribe-auth/AWJVQQXU7RDFKDWVI5BMIFT3PS2ZXAVCNFSM6AAAAACE2SBTSOVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZTEMRVGUZDIMZTGY>
 .
 You are receiving this because you were mentioned.Message ID:
 ***@***.***>
 
 | 
    
| 
           👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the   | 
    
Updates
Comments
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)
Improper Removal of Sensitive Information Before Storage or Transfer (CWE-212)
Suggest improvements
Suggestions are submitted as a pull request to be reviewed by the GitHub Security Curators team.
Reason for change *