flamencist / flamencist/CopyCssSelector

CVE-2022-41940 (Medium) detected in engine.io-3.2.1.tgz

Open
#31 0 comments 0 reactions 0 assignees View on GitHub
Mend: dependency security vulnerability
Dominant language
JavaScript
Stars
28
Forks
3
PR merge metrics
No merged PRs in 30d

Description

## CVE-2022-41940 - Medium Severity Vulnerability
Vulnerable Library - engine.io-3.2.1.tgz

The realtime engine behind Socket.IO. Provides the foundation of a bidirectional connection between client and server


Library home page: https://registry.npmjs.org/engine.io/-/engine.io-3.2.1.tgz


Path to dependency file: /package.json


Path to vulnerable library: /node_modules/engine.io/package.json


Dependency Hierarchy:
- karma-4.4.1.tgz (Root Library)
- socket.io-2.1.1.tgz
- :x: **engine.io-3.2.1.tgz** (Vulnerable Library)


Vulnerability Details



Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the engine.io package, including those who uses depending packages like socket.io. There is no known workaround except upgrading to a safe version. There are patches for this issue released in versions 3.6.1 and 6.2.1.

Publish Date: 2022-11-22

URL: CVE-2022-41940



CVSS 3 Score Details (6.5)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High


For more information on CVSS3 Scores, click here.


Suggested Fix

Type: Upgrade version


Origin: https://github.com/socketio/engine.io/security/advisories/GHSA-r7qp-cfhv-p84w


Release Date: 2022-11-22


Fix Resolution (engine.io): 3.6.1


Direct dependency fix Resolution (karma): 6.0.0

***
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.