Description
Affected versions of engine.io-client do not verify certificates by default, and as such may be vulnerable to Man-in-the-Middle attacks.
The vulnerability is related to the way that node.js handles the rejectUnauthorized setting.
Recommendation
Update the engine.io-client package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.6.9
- Patched version(s): 1.6.9
References
- GHSA-4r4m-hjwj-43p8
- www.cigital.com
- www.npmjs.com
- CVE-2016-10536
- CWE-300
- CAPEC-310
- OWASP 2021-A6
- OWASP 2021-A7
Related Issues
- Resources Downloaded over Insecure Protocol in igniteui - CVE-2016-10552
- XSS in client rendered block templates in rendr - CVE-2016-1000230
- chromedriver Downloads Resources over HTTP - CVE-2016-10579
- Downloads Resources over HTTP in jser-stat - CVE-2016-10592
You might also like:
- Tags:
- npm
- engine.io-client
Anything's wrong? Let us know Last updated on September 07, 2023


