GHSA-r2gr-fhmr-66c5
Dashboard / Vulnerabilities / GHSA-r2gr-fhmr-66c5
GHSA-r2gr-fhmr-66c5
Summary: Duplicate Advisory: "Arbitrary code execution in socket.io-file"
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-6495-8jvh-f28x. This link is maintained to preserve external references. ## Original Description "The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer."
References: https://nvd.nist.gov/vuln/detail/CVE-2020-24807, https://github.com/advisories/GHSA-6495-8jvh-f28x, https://github.com/rico345100/socket.io-file, https://www.npmjs.com/advisories/1564, https://www.npmjs.com/package/socket.io-file
Affected packages
Package
Name: socket.io-file
Purl: pkg:npm/socket.io-file
Affected ranges
Type: SEMVER
Events:
