This repository has been archived by the owner on Jan 18, 2024. It is now read-only.
WS-2020-0443 (High) detected in socket.io-2.3.0.tgz #43
Labels
security vulnerability
Security vulnerability detected by WhiteSource
WS-2020-0443 - High Severity Vulnerability
node.js realtime framework server
Library home page: https://registry.npmjs.org/socket.io/-/socket.io-2.3.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/socket.io/package.json
Dependency Hierarchy:
Found in base branch: master
In socket.io in versions 1.0.0 to 2.3.0 is vulnerable to Cross-Site Websocket Hijacking, it allows an attacker to bypass origin protection using special symbols include "`" and "$".
Publish Date: 2020-02-20
URL: WS-2020-0443
Base Score Metrics:
Type: Upgrade version
Origin: https://hackerone.com/reports/931197
Release Date: 2020-02-20
Fix Resolution (socket.io): 2.4.0
Direct dependency fix Resolution (karma): 5.1.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: