flamencist / flamencist/CopyCssSelector

CVE-2020-36048 (High) detected in engine.io-3.2.1.tgz

Open
#15 0 comments 0 reactions 0 assignees View on GitHub
Mend: dependency security vulnerability
Dominant language
JavaScript
Stars
28
Forks
3
PR merge metrics
No merged PRs in 30d

Description

## CVE-2020-36048 - High Severity Vulnerability
Vulnerable Library - engine.io-3.2.1.tgz

The realtime engine behind Socket.IO. Provides the foundation of a bidirectional connection between client and server


Library home page: https://registry.npmjs.org/engine.io/-/engine.io-3.2.1.tgz


Path to dependency file: /package.json


Path to vulnerable library: /node_modules/engine.io/package.json


Dependency Hierarchy:
- karma-4.4.1.tgz (Root Library)
- socket.io-2.1.1.tgz
- :x: **engine.io-3.2.1.tgz** (Vulnerable Library)


Vulnerability Details



Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.

Publish Date: 2021-01-08

URL: CVE-2020-36048



CVSS 3 Score Details (7.5)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High


For more information on CVSS3 Scores, click here.


Suggested Fix

Type: Upgrade version


Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36048


Release Date: 2021-01-08


Fix Resolution (engine.io): 3.6.0


Direct dependency fix Resolution (karma): 6.0.0

***
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing /package.json and the dependency hierarchy for karma-4.4.1, socket.io-2.1.1, and engine.io-3.2.1. Check the available upgrade path to the stated fixed versions, then verify that the vulnerable engine.io version is no longer installed and that the extension's existing checks still pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.