VYPR

Sockjs

by Sockjs Project

CVEs (2)

  • CVE-2020-8823MedFeb 10, 2020
    risk 0.33cvss 6.1epss 0.02

    htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter.

  • CVE-2020-7693MedJul 9, 2020
    risk 0.28cvss 5.3epss 0.05

    Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.