5.3

CVE-2020-28481

Exploit

Insecure Defaults

The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SocketSocket.Io SwPlatformnode.js Version < 2.4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.494
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
report@snyk.io 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

https://github.com/socketio/socket.io/issues/3671
Third Party Advisory
Exploit
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1056358
Third Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1056357
Third Party Advisory
https://snyk.io/vuln/SNYK-JS-SOCKETIO-1024859
Third Party Advisory