1.0.7
13 years ago
4 years ago
Known vulnerabilities in the sockjs-tornado package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
sockjs-tornado is a Python server side counterpart of SockJS-client browser library running on top of Tornado framework. Affected versions of this package are vulnerable to Cross Site Scripting (XSS) via the HTMLFILE_HEAD template which uses unsanitized user data. An incomplete fix was issued for version 1.0.6. How to fix Cross Site Scripting (XSS)? Upgrade | [,1.0.7) |