First published: Tue Jan 19 2021(Updated: )
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
Credit: report@snyk.io report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
npm/socket.io | <2.4.0 | 2.4.0 |
Socket Socket.io | <2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28481 is a vulnerability in the package socket.io before 2.4.0 that is caused by insecure defaults due to CORS misconfiguration.
CVE-2020-28481 affects the affected software by allowing all domains to be whitelisted by default.
The severity of CVE-2020-28481 is medium with a severity value of 4.3.
To fix CVE-2020-28481, upgrade to version 2.4.0 or later of the socket.io package.
You can find more information about CVE-2020-28481 at the following references: [link1], [link2], [link3].