Vulnerabilities > Sockjs Project

DATE CVE VULNERABILITY TITLE RISK
2020-07-09 CVE-2020-7693 Improper Handling of Exceptional Conditions vulnerability in Sockjs Project Sockjs
Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps.
network
low complexity
sockjs-project CWE-755
5.0
2020-02-10 CVE-2020-8823 Cross-site Scripting vulnerability in Sockjs Project Sockjs
htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter.
4.3