Vulnerability GHSA-fxwf-4rqh-v8g3
Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 years ago
January 20, 2021 at 09:22 PM UTC
CORS misconfiguration in socket.io
0.3.8 - 2.3.0
0.3.8 - 2.3.0
Summary
CORS misconfiguration in socket.io
Details
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
2 years ago
socket.io has an unhandled 'error' event
0.3.8 - 2.5.0 and 3.0.0 - 4.6.1 GHSA-25hc-qcg6-38wj
0.3.8 - 2.5.0 and 3.0.0 - 4.6.1 GHSA-25hc-qcg6-38wj
High Risk
7 years ago
Insecure randomness in socket.io
0.3.8 - 0.9.6 GHSA-qv2v-m59f-v5fw
0.3.8 - 0.9.6 GHSA-qv2v-m59f-v5fw
Impacted packages
Timeline
Published
5 years ago
January 20, 2021 at 09:22 PM UTC
Fixed (2.4.0)
Unknown
Unknown
Last Modified
1 year ago
January 14, 2025 at 08:56 AM UTC