Denial of Service Vulnerability in Engine.IO by Socket.IO
CVE-2020-36048

7.5HIGH

Key Information:

Vendor

Socket

Status
Vendor
CVE Published:
8 January 2021

What is CVE-2020-36048?

Engine.IO, a popular web socket library from Socket.IO, is susceptible to denial of service attacks in versions prior to 4.0.0. Attackers can exploit this vulnerability by sending specially crafted POST requests to the long polling transport method, leading to excessive resource consumption. This behavior can result in service interruption and decreased application performance. It is crucial to update to the latest version to mitigate these risks and ensure the security of applications reliant on this library.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.