org.webjars.npm:socket.io-parser@4.2.2 vulnerabilities
WebJar for socket.io-parser
-
latest version
4.2.2
-
first published
8 years ago
-
latest version published
4 months ago
-
licenses detected
- [2.2.4,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.webjars.npm:socket.io-parser package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
org.webjars.npm:socket.io-parser is a socket.io protocol parser Affected versions of this package are vulnerable to Denial of Service (DoS) due to insufficient validation when decoding a packet. An attacker can send an event with a name like
How to fix Denial of Service (DoS)? Upgrade |
[3.4.0,3.4.3)
[4.0.0,4.2.3)
|