console-io@1.3.9 vulnerabilities

Web console

  • latest version

    14.1.0

  • latest non vulnerable version

  • first published

    10 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the console-io package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Authentication Bypass

    console-io is a web console used in Cloud Commander.

    Affected versions of this package are vulnerable to Authentication Bypass. Does not require authentication for socket.io, thus allowing attackers to send and execute shell commands over a websocket.

    How to fix Authentication Bypass?

    Upgrade console-io to version 2.3.0 or higher.

    <2.3.0