Количество 5
Количество 5
CVE-2019-13611
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.
CVE-2019-13611
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.
CVE-2019-13611
An issue was discovered in python-engineio through 3.8.2. There is a C ...
GHSA-j3jp-gvr5-7hwq
python-engineio vulnerable to Cross-Site Request Forgery (CSRF)
BDU:2020-01383
Уязвимость протокола WebSocket веб-сервера Engine.IO, связанная с подделкой межсайтовых закпросов, позволяющая нарушителю выполнять произвольные действия в уязвимой системе
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-13611 An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted. | CVSS3: 8.8 | 0% Низкий | больше 6 лет назад | |
CVE-2019-13611 An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted. | CVSS3: 8.8 | 0% Низкий | больше 6 лет назад | |
CVE-2019-13611 An issue was discovered in python-engineio through 3.8.2. There is a C ... | CVSS3: 8.8 | 0% Низкий | больше 6 лет назад | |
GHSA-j3jp-gvr5-7hwq python-engineio vulnerable to Cross-Site Request Forgery (CSRF) | CVSS3: 8.8 | 0% Низкий | больше 6 лет назад | |
BDU:2020-01383 Уязвимость протокола WebSocket веб-сервера Engine.IO, связанная с подделкой межсайтовых закпросов, позволяющая нарушителю выполнять произвольные действия в уязвимой системе | CVSS3: 8.8 | 0% Низкий | больше 6 лет назад |
Уязвимостей на страницу