QID 982966
QID 982966: Nodejs (npm) Security Update for socket.io (GHSA-fxwf-4rqh-v8g3)
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fxwf-4rqh-v8g3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-fxwf-4rqh-v8g3 -
github.com/advisories/GHSA-fxwf-4rqh-v8g3
CVEs related to QID 982966
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fxwf-4rqh-v8g3 | socket.io |
|