HIGH
yarnpkg-socket.io-parser: a denial of service (memory consumption) via a large packet because a concatenation approach is used
Published Jan 7, 2021
7.5
HIGHCVSS 3.1
EPSS 2.67%
Description
socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.
Affected products
No data.
- < 3.4.1
No data.
Red Hat 3scale API Management Platform 2
system
Affected
Red Hat Quay 3
quay/quay-builder-qemu-rhcos-rhel8
Not affected
Red Hat Quay 3
quay/quay-rhel8
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat 3scale API Management Platform 2 | system | Affected | n/a |
| Red Hat Quay 3 | quay/quay-builder-qemu-rhcos-rhel8 | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Fix deferred | n/a |
socket.io-parser
npm
Introduced 0 Fixed 3.3.2socket.io-parser
npm
Introduced 3.4.0 Fixed 3.4.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | socket.io-parser | 0 | 3.3.2 |
| npm | socket.io-parser | 3.4.0 | 3.4.1 |
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2020-36049 Vendor Advisory
- https://blog.caller.xyz/socketio-engineio-dos/ x_refsource_MISCExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1918266 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1424 Advisory
- https://github.com/advisories/GHSA-xfhh-g9f5-x4m4 Advisory
- https://github.com/bcaller/kill-engine-io x_refsource_MISCThird Party Advisory
- https://github.com/socketio/socket.io-parser/commit/dcb942d24db97162ad16a67c2a0cf30875342d55 x_refsource_MISCPatchThird Party Advisory
- https://github.com/socketio/socket.io-parser/releases/tag/3.3.2
- https://github.com/socketio/socket.io-parser/releases/tag/3.4.1
- https://nvd.nist.gov/vuln/detail/CVE-2020-36049
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1056753
- https://www.cve.org/CVERecord?id=CVE-2020-36049
- https://www.npmjs.com/package/socket.io-parser
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-36049 | Vendor Advisory | |
| https://blog.caller.xyz/socketio-engineio-dos/ | x_refsource_MISCExploitThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1918266 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1424 | Advisory | |
| https://github.com/advisories/GHSA-xfhh-g9f5-x4m4 | Advisory | |
| https://github.com/bcaller/kill-engine-io | x_refsource_MISCThird Party Advisory | |
| https://github.com/socketio/socket.io-parser/commit/dcb942d24db97162ad16a67c2a0cf30875342d55 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/socketio/socket.io-parser/releases/tag/3.3.2 | ||
| https://github.com/socketio/socket.io-parser/releases/tag/3.4.1 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-36049 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1056753 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-36049 | ||
| https://www.npmjs.com/package/socket.io-parser |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 7, 2021
Updated Aug 4, 2024
Reserved Jan 4, 2021
Link CVE-2020-36049
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-1424 GHSA-XFHH-G9F5-X4M4 Assigner mitre
Published Jan 7, 2021
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2021-1424