High severity8.5NVD Advisory· Published Apr 29, 2020· Updated Jun 17, 2026
CVE-2020-11020
CVE-2020-11020
Description
Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication bypass in the extension system. The vulnerability allows any client to bypass checks put in place by server-side extensions, by appending extra segments to the message channel. It is patched in versions 1.0.4, 1.1.3 and 1.2.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fayeRubyGems | >= 0.5.0, < 1.0.4 | 1.0.4 |
fayeRubyGems | >= 1.1.0, < 1.1.3 | 1.1.3 |
fayeRubyGems | >= 1.2.0, < 1.2.5 | 1.2.5 |
Affected products
4cpe:2.3:a:faye_project:faye:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:faye_project:faye:*:*:*:*:*:node.js:*:*range: >0.5.0,<1.0.4
- cpe:2.3:a:faye_project:faye:*:*:*:*:*:ruby:*:*range: >0.5.0,<1.0.4
Patches
Vulnerability mechanics
References
5- github.com/faye/faye/commit/65d297d341b607f3cb0b5fa6021a625a991cc30envdPatchThird Party AdvisoryWEB
- github.com/faye/faye/security/advisories/GHSA-qpg4-4w7w-2mq5nvdExploitMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-qpg4-4w7w-2mq5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-11020ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/faye/CVE-2020-11020.ymlghsaWEB
News mentions
0No linked articles in our index yet.