Vulnerability GHSA-qv2v-m59f-v5fw

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
7 years ago
November 07, 2018 at 12:29 AM UTC
Insecure randomness in socket.io
0.3.8 - 0.9.6
0.3.8 - 0.9.6

Summary

Insecure randomness in socket.io

Details

Affected versions of socket.io depend on Math.random() to create socket IDs, and therefore the IDs are predictable. With enough information on prior IDs, an attacker may be able to guess the socket ID and gain access to socket.io servers without authorization.

Recommendation

Update to v0.9.7 or later.

Impacted packages

Timeline

Published
7 years ago
November 07, 2018 at 12:29 AM UTC
Fixed (0.9.7)
Unknown
Unknown
Last Modified
2 years ago
November 08, 2023 at 03:59 AM UTC