Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2gr-fhmr-66c5

Опубликовано: 10 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Duplicate Advisory: "Arbitrary code execution in socket.io-file"

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-6495-8jvh-f28x. This link is maintained to preserve external references.

Original Description

"The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer."

Пакеты

Наименование

socket.io-file

npm
Затронутые версииВерсия исправления

<= 2.0.31

Отсутствует

7.8 High

CVSS3

Дефекты

CWE-20

7.8 High

CVSS3

Дефекты

CWE-20