GHSA-qv2v-m59f-v5fw

    Dashboard / Vulnerabilities / GHSA-qv2v-m59f-v5fw

    GHSA-qv2v-m59f-v5fw

    Published: 7 Nov 2018Last Modified: 8 Nov 2023

    Summary: Insecure randomness in socket.io

    Details: Affected versions of `socket.io` depend on `Math.random()` to create socket IDs, and therefore the IDs are predictable. With enough information on prior IDs, an attacker may be able to guess the socket ID and gain access to socket.io servers without authorization. ## Recommendation Update to v0.9.7 or later.

    Affected packages

    Package

    Name: socket.io

    Purl: pkg:npm/socket.io

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.9.7

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High