CVE-2017-16031
Last modified
CVE-2017-16031 is a vulnerability of currently unknown severity. Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. EPSS estimates a 2.00% chance of exploitation in the next 30 days.
Description
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Socket | Socket.Io | <= 0.9.6 |
References
- https://github.com/socketio/socket.io/commit/67b4eb9abdf111dfa9be4176d1709374a2b4ded8Issue Tracking, Patch, Third Party Advisory
- https://github.com/socketio/socket.io/issues/856Issue Tracking, Third Party Advisory
- https://github.com/socketio/socket.io/pull/857Issue Tracking, Third Party Advisory
- https://nodesecurity.io/advisories/321Third Party Advisory
- https://github.com/socketio/socket.io/commit/67b4eb9abdf111dfa9be4176d1709374a2b4ded8Issue Tracking, Patch, Third Party Advisory
- https://github.com/socketio/socket.io/issues/856Issue Tracking, Third Party Advisory
- https://github.com/socketio/socket.io/pull/857Issue Tracking, Third Party Advisory
- https://nodesecurity.io/advisories/321Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-16031?
How severe is CVE-2017-16031?
How do I fix CVE-2017-16031?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-16024The sync-exec module is used to simulate child_process.execS…
- CVE-2017-16025Nes is a websocket extension library for hapi. Hapi is a web…
- CVE-2017-16026Request is an http client. If a request is made using ```mul…
- CVE-2017-16028react-native-meteor-oauth is a library for Oauth2 login to a…
- CVE-2017-16029hostr is a simple web server that serves up the contents of …
- CVE-2017-16030Useragent is used to parse useragent headers. It uses severa…
- CVE-2017-16035The hubl-server module is a wrapper for the HubL Development…
- CVE-2017-16036`badjs-sourcemap-server` receives files sent by `badjs-sourc…
- CVE-2017-16037`gomeplus-h5-proxy` is vulnerable to a directory traversal i…
- CVE-2017-16038`f2e-server` 1.12.11 and earlier is vulnerable to a director…
- CVE-2017-16039`hftp` is a static http or ftp server `hftp` is vulnerable t…
- CVE-2017-1604IBM Maximo Anywhere 7.5 and 7.6 is vulnerable to cross-site …
Are you affected by CVE-2017-16031?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
