ZeroHour

CVE-2020-28481

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p52
Published
()
Modified
Description

The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.

Vendors
socket
Products
socket.io
Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.