Vulnerabilities/

CORS misconfiguration in socket.io

Severity:
Medium

Description

The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.

Recommendation

Update the socket.io package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
socket.io
Anything's wrong? Let us know Last updated on September 11, 2023