CVE-2020-28481: Insecure Defaults
Published Jan 19, 2021
·Updated
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
Affected Software
2 affected componentsFixes available
npm/socket.io<2.4.0
2.4.0
Socket Socket.io Node.js<2.4.0
Event History
Jan 19, 2021
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Jan 20, 2021
Advisory Published
09:22 PM
Frequently Asked Questions
1
What is CVE-2020-28481?
CVE-2020-28481 is a vulnerability in the package socket.io before 2.4.0 that is caused by insecure defaults due to CORS misconfiguration.
2
How does CVE-2020-28481 affect the affected software?
CVE-2020-28481 affects the affected software by allowing all domains to be whitelisted by default.
3
What is the severity of CVE-2020-28481?
The severity of CVE-2020-28481 is medium with a severity value of 4.3.
4
How can I fix CVE-2020-28481?
To fix CVE-2020-28481, upgrade to version 2.4.0 or later of the socket.io package.
5
Where can I find more information about CVE-2020-28481?
You can find more information about CVE-2020-28481 at the following references: [link1], [link2], [link3].