Lucene search

K
osvGoogleOSV:CVE-2020-28481
HistoryJan 19, 2021 - 3:15 p.m.

CVE-2020-28481

2021-01-1915:15:12
Google
osv.dev
3
socket.io
insecure defaults
cors
misconfiguration
whitelisted
software

AI Score

6.7

Confidence

High

EPSS

0.002

Percentile

53.0%

The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.

AI Score

6.7

Confidence

High

EPSS

0.002

Percentile

53.0%