SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7693

Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps.

MEDIUM 5.3EPSS 4.98%

Does this matter?

Lower severity and a low EPSS score (4.98%). Track it; it rarely justifies an emergency change on its own.

Description

Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
4.98% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-755
Affected
sockjs project/sockjs
Source
report@snyk.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.