QID 982737
QID 982737: Nodejs (npm) Security Update for sockjs (GHSA-c9g6-9335-x697)
Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c9g6-9335-x697 for updates pertaining to this vulnerability.
Vendor References
- GHSA-c9g6-9335-x697 -
github.com/advisories/GHSA-c9g6-9335-x697
CVEs related to QID 982737
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c9g6-9335-x697 | sockjs |
|