faye@1.2.0 vulnerabilities
Simple pub/sub messaging for the web
-
latest version
1.4.0
-
latest non vulnerable version
-
first published
14 years ago
-
latest version published
4 years ago
-
licenses detected
- >=0.5.0 <1.3.0
Direct Vulnerabilities
Known vulnerabilities in the faye package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
faye is a simple pub/sub messaging for the web. Affected versions of this package are vulnerable to Improper Certificate Validation due to not implementing certificate verification by default, meaning that it does not check whether the server presents a valid and trusted TLS certificate for the expected hostname. How to fix Improper Certificate Validation? Upgrade |
<1.4.0
|
faye is a simple pub/sub messaging for the web. Affected versions of this package are vulnerable to Improper Access Control. The Server parses channels in a way that means any channel namespaced under How to fix Improper Access Control? Upgrade |
<1.0.4
>=1.1.0 <1.1.3
>=1.2.0 <1.2.5
|