Vulnerability GHSA-qv2v-m59f-v5fw
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
7 years ago
November 07, 2018 at 12:29 AM UTC
Insecure randomness in socket.io
0.3.8 - 0.9.6
0.3.8 - 0.9.6
Summary
Insecure randomness in socket.io
Details
Affected versions of socket.io depend on Math.random() to create socket IDs, and therefore the IDs are predictable. With enough information on prior IDs, an attacker may be able to guess the socket ID and gain access to socket.io servers without authorization.
Recommendation
Update to v0.9.7 or later.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
2 years ago
socket.io has an unhandled 'error' event
0.3.8 - 2.5.0 and 3.0.0 - 4.6.1 GHSA-25hc-qcg6-38wj
0.3.8 - 2.5.0 and 3.0.0 - 4.6.1 GHSA-25hc-qcg6-38wj
Medium Risk
5 years ago
CORS misconfiguration in socket.io
0.3.8 - 2.3.0 GHSA-fxwf-4rqh-v8g3
0.3.8 - 2.3.0 GHSA-fxwf-4rqh-v8g3
Impacted packages
Timeline
Published
7 years ago
November 07, 2018 at 12:29 AM UTC
Fixed (0.9.7)
Unknown
Unknown
Last Modified
2 years ago
November 08, 2023 at 03:59 AM UTC