HIGH
yarnpkg-socket.io/engine.io: allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport
Published Jan 7, 2021
7.5
HIGHCVSS 3.1
EPSS 3.28%
Description
Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
Affected products
No data.
No data.
Red Hat Quay 3
quay/quay-builder-qemu-rhcos-rhel8
Fix deferred
Red Hat Quay 3
quay/quay-rhel8
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Quay 3 | quay/quay-builder-qemu-rhcos-rhel8 | Fix deferred | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Fix deferred | n/a |
engine.io
npm
Introduced 0 Fixed 3.6.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | engine.io | 0 | 3.6.0 |
Remediation
Red Hat statement
Red Hat Quay uses engine.io as a dependency of karma. Karma and therefore engine.io are only used at build time, and not during runtime, making this vulnerability low impact for Red Hat Quay.
Weaknesses (1)
References (11)
- https://access.redhat.com/security/cve/CVE-2020-36048 Vendor Advisory
- https://blog.caller.xyz/socketio-engineio-dos x_refsource_MISCExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1918265 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1064 Advisory
- https://github.com/advisories/GHSA-j4f2-536g-r55m Advisory
- https://github.com/bcaller/kill-engine-io x_refsource_MISCThird Party Advisory
- https://github.com/socketio/engine.io/commit/58e274c437e9cbcf69fd913c813aad8fbd253703
- https://github.com/socketio/engine.io/commit/734f9d1268840722c41219e69eb58318e0b2ac6b x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-36048
- https://snyk.io/vuln/SNYK-JS-ENGINEIO-1056749
- https://www.cve.org/CVERecord?id=CVE-2020-36048
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-36048 | Vendor Advisory | |
| https://blog.caller.xyz/socketio-engineio-dos | x_refsource_MISCExploitThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1918265 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1064 | Advisory | |
| https://github.com/advisories/GHSA-j4f2-536g-r55m | Advisory | |
| https://github.com/bcaller/kill-engine-io | x_refsource_MISCThird Party Advisory | |
| https://github.com/socketio/engine.io/commit/58e274c437e9cbcf69fd913c813aad8fbd253703 | ||
| https://github.com/socketio/engine.io/commit/734f9d1268840722c41219e69eb58318e0b2ac6b | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-36048 | ||
| https://snyk.io/vuln/SNYK-JS-ENGINEIO-1056749 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-36048 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 7, 2021
Updated Aug 4, 2024
Reserved Jan 4, 2021
Link CVE-2020-36048
CISA Vulnrichment
No data
GitHub
Link GHSA-J4F2-536G-R55M