Lucene search

K
nodejsAnonymousNODEJS:1609
HistoryFeb 19, 2021 - 10:40 p.m.

Insecure Default Configuration

2021-02-1922:40:51
Anonymous
www.npmjs.com
68
socket.io
insecure defaults
cors misconfiguration
whitelisted domains
update required

EPSS

0.002

Percentile

53.0%

Overview

Affected versions of socket.io are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.

Recommendation

Update to version 2.4.0 or later.

References

EPSS

0.002

Percentile

53.0%