Back

HIGH

yarnpkg-socket.io/engine.io: allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport

Published Jan 7, 2021

Description

Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.

Affected products

Remediation

Red Hat statement

Red Hat Quay uses engine.io as a dependency of karma. Karma and therefore engine.io are only used at build time, and not during runtime, making this vulnerability low impact for Red Hat Quay.

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Jan 7, 2021
Updated Aug 4, 2024
Reserved Jan 4, 2021

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Jan 8, 2020
Bugzilla 1918265

ENISA EUVD

Assigner mitre
Published Jan 7, 2021
Updated Aug 4, 2024