Socket Socket.io-parser 3.4.3 for Node.js

CPE Details

Socket Socket.io-parser 3.4.3 for Node.js
3.4.3
2023-06-02
15h20 +00:00
2023-06-22
14h09 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:socket:socket.io-parser:3.4.3:*:*:*:*:node.js:*:*

Informations

Vendor

socket

Product

socket.io-parser

Version

3.4.3

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-2421 2022-10-24 22h00 +00:00 Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.
10
Critique