ZeroHour

CVE-2020-7693

PoC ×4
CVSS 3.1
5.3 medium
EPSS
5%p92
Published
()
Modified
Description

Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

Vendors
sockjs project
Products
sockjs
Weakness
CWE-755
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.