QID 983232
QID 983232: Nodejs (npm) Security Update for droppy (GHSA-rhvc-x32h-5526)
Affected versions of `droppy` are vulnerable to cross-site socket forgery. The package does not perform verification for cross-domain websocket requests, and as a result, an attacker can create a web page that opens up a websocket connection on behalf of the user visiting the page. The attacker can then perform any action that the target user could, including adding a new admin account under their control, or deleting others.
## Recommendation
Update to version 3.5.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rhvc-x32h-5526 for updates pertaining to this vulnerability.
Vendor References
- GHSA-rhvc-x32h-5526 -
github.com/advisories/GHSA-rhvc-x32h-5526
CVEs related to QID 983232
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rhvc-x32h-5526 | droppy |
|