Socket socket.io-parser 4.0.1 Release Candidate 3 for Node.js

CPE Details

Socket socket.io-parser 4.0.1 Release Candidate 3 for Node.js
4.0.1
2021-01-08
18h54 +00:00
2021-01-08
18h54 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:socket:socket.io-parser:4.0.1:rc3:*:*:*:node.js:*:*

Informations

Vendor

socket

Product

socket.io-parser

Version

4.0.1

Update

rc3

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-2421 2022-10-24 22h00 +00:00 Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.
10
Critique