—
PYSEC-2019-170
Quick fix
PYSEC-2019-170 — python-engineio: upgrade to the fixed version with the command below.
pip install --upgrade 'python-engineio>=3.9.0'Details
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/python-engineio
Introduced in:
0Fixed in: 3.9.0Fix
pip install --upgrade 'python-engineio>=3.9.0'