Skip to main content

Origin Validation Error

CVE-2020-28481

Severity Medium
Score 4.3/10

Summary

The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default. The fix got reverted at 2.4.1 due to crashes caused by it, the recommendation is to upgrade to v3.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-346 - Origin Validation Error

The software does not properly verify that the source of data or communication is valid.

Advisory Timeline

  • Published