MEDIUM5.3
GHSA-c9g6-9335-x697
Improper Input Validation in SocksJS-Node
Quick fix
GHSA-c9g6-9335-x697 — sockjs: upgrade to the fixed version with the command below.
npm install sockjs@0.3.20Details
Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7693[ADVISORY]
- https://github.com/sockjs/sockjs-node/issues/252[WEB]
- https://github.com/sockjs/sockjs-node/pull/265[WEB]
- https://github.com/sockjs/sockjs-node/commit/dd7e642cd69ee74385825816d30642c43e051d16[WEB]
- https://github.com/andsnw/sockjs-dos-py[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-575448[WEB]
- https://snyk.io/vuln/SNYK-JS-SOCKJS-575261[WEB]
- https://www.npmjs.com/package/sockjs[WEB]