Vulnerabilities > Faye Project

DATE CVE VULNERABILITY TITLE RISK
2020-07-31 CVE-2020-15134 Improper Certificate Validation vulnerability in Faye Project Faye
Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes.
network
high complexity
faye-project CWE-295
8.7
2020-04-29 CVE-2020-11020 Improper Authentication vulnerability in Faye Project Faye
Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication bypass in the extension system.
network
low complexity
faye-project CWE-287
critical
9.8