CVE-2020-7693

MEDIUM5.3EPSS 16.0%

Improper Input Validation in SocksJS-Node

Published: 4/13/2021Modified: 9/3/2024
Also known as:GHSA-c9g6-9335-x697

Description

Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References (8)