GHSA-qm95-pgcg-qqfq
CRITICALCVE-2022-2421Due to improper type validation in the socket.io-parser library (which is used by the socket.io and socket.io-client packages to encode and decode Socket.IO packets), it is possible to overwrite the placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.
- Affected
- >= 4.0.0, < 4.0.5, < 3.3.3, >= 4.1.0, < 4.2.1, >= 3.4.0, < 3.4.2
- Fixed in
- 4.0.5
- Weakness
- CWE-20
- Published
- 2022-10-26
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereference