Описание
The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Ссылки
- Third Party Advisory
- ProductThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.31 (включая)
cpe:2.3:a:socket.io-file_project:socket.io-file:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 70%
0.00654
Низкий
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
EPSS
Процентиль: 70%
0.00654
Низкий
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-20