faye@1.0.4 vulnerabilities

Simple pub/sub messaging for the web

Direct Vulnerabilities

Known vulnerabilities in the faye package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Improper Certificate Validation

faye is a simple pub/sub messaging for the web.

Affected versions of this package are vulnerable to Improper Certificate Validation due to not implementing certificate verification by default, meaning that it does not check whether the server presents a valid and trusted TLS certificate for the expected hostname.

How to fix Improper Certificate Validation?

Upgrade faye to version 1.4.0 or higher.

<1.4.0
  • H
Cross-Site Request Forgery (CSRF)

faye is a simple pub/sub messaging for the web.

Affected versions of this package are vulnerable to Cross-Site Request Forgery (CSRF). Rosetta Flash (alphanum only swf converter) can be used as a callback at a JSONP endpoint, and as a result, send data across domains.

How to fix Cross-Site Request Forgery (CSRF)?

Upgrade faye to version 1.1.0 or higher.

<1.1.0