Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.
The product does not handle or incorrectly handles an exceptional condition.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-JS-SOCKJS-575261 | third party advisory exploit |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-575448 | third party advisory exploit |
https://github.com/sockjs/sockjs-node/issues/252 | patch third party advisory exploit |
https://github.com/sockjs/sockjs-node/pull/265 | third party advisory patch |
https://github.com/andsnw/sockjs-dos-py | third party advisory exploit |
https://github.com/sockjs/sockjs-node/commit/dd7e642cd69ee74385825816d30642c43e051d16 | third party advisory patch |