CVE-2020-28481
MEDIUMCVSS 4.3/10EPSS 0.73%
Last modified
CVE-2020-28481 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Socket | Socket.Io | < 2.4.0 |
References
- https://github.com/socketio/socket.io/issues/3671Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1056358Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1056357Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-SOCKETIO-1024859Third Party Advisory
- https://github.com/socketio/socket.io/issues/3671Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1056358Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1056357Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-SOCKETIO-1024859Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-28481?
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
How severe is CVE-2020-28481?
CVE-2020-28481 has a CVSS score of 4.3/10 (MEDIUM severity). The EPSS model estimates a 0.73% probability of exploitation in the next 30 days.
How do I fix CVE-2020-28481?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-28476Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-28477This affects all versions of package immer.7.5
- CVE-2020-28478This affects the package gsap before 3.6.0.7.5
- CVE-2020-28479The package jointjs before 3.3.0 are vulnerable to Denial of…7.5
- CVE-2020-2848Vulnerability in the Oracle Depot Repair product of Oracle E…8.2
- CVE-2020-28480The package jointjs before 3.3.0 are vulnerable to Prototype…9.8
- CVE-2020-28482This affects the package fastify-csrf before 3.0.0. 1. The g…8.8
- CVE-2020-28483This affects all versions of package github.com/gin-gonic/gi…7.1
- CVE-2020-28487This affects the package vis-timeline before 7.4.4. An attac…6.8
- CVE-2020-28488Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-2849Vulnerability in the Oracle Depot Repair product of Oracle E…8.2
- CVE-2020-28490The package async-git before 1.13.2 are vulnerable to Comman…9.8
Are you affected by CVE-2020-28481?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
