Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv2v-m59f-v5fw

Опубликовано: 07 нояб. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Insecure randomness in socket.io

Affected versions of socket.io depend on Math.random() to create socket IDs, and therefore the IDs are predictable. With enough information on prior IDs, an attacker may be able to guess the socket ID and gain access to socket.io servers without authorization.

Recommendation

Update to v0.9.7 or later.

Пакеты

Наименование

socket.io

npm
Затронутые версииВерсия исправления

<= 0.9.6

0.9.7

EPSS

Процентиль: 59%
0.00385
Низкий

7.5 High

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive information.

EPSS

Процентиль: 59%
0.00385
Низкий

7.5 High

CVSS3

Дефекты

CWE-330