Description
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
Recommendation
Update the socket.io package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.4.0
- Patched version(s): 2.4.0
References
Related Issues
- Path Traversal in socket.io-file - CVE-2020-15779
- Resource exhaustion in socket.io-parser - CVE-2020-36049
- File restriction bypass in socket.io-file - CVE-2020-24807
- socket.io has an unhandled 'error' event - CVE-2024-38355
You might also like:
- Tags:
- npm
- socket.io
Anything's wrong? Let us know Last updated on September 11, 2023


