Origin Validation Error
CVE-2020-28481
Summary
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default. The fix got reverted at 2.4.1 due to crashes caused by it, the recommendation is to upgrade to v3.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- LOW
- NONE
CWE-346 - Origin Validation Error
The software does not properly verify that the source of data or communication is valid.
Advisory Timeline
- Published