Description
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
Remediation
References
https://github.com/socketio/socket.io/issues/3671
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1056358
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1056357
https://snyk.io/vuln/SNYK-JS-SOCKETIO-1024859
Related Vulnerabilities
CVE-2023-26149 Vulnerability in maven package org.webjars.npm:quill-mention
CVE-2018-3717 Vulnerability in npm package anywhere
CVE-2018-3719 Vulnerability in maven package org.webjars.npm:mixin-deep
CVE-2020-28459 Vulnerability in npm package markdown-it-decorate
CVE-2022-45397 Vulnerability in maven package org.jenkins-ci.plugins:osf-builder-suite-xml-linter