QID 982623
QID 982623: Nodejs (npm) Security Update for socket.io-file (GHSA-r2gr-fhmr-66c5)
"The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer."
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-r2gr-fhmr-66c5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-r2gr-fhmr-66c5 -
github.com/advisories/GHSA-r2gr-fhmr-66c5
CVEs related to QID 982623
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r2gr-fhmr-66c5 | socket.io-file |
|