-
Notifications
You must be signed in to change notification settings - Fork 0
Update dependency socket.io to v2 [SECURITY] #2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-socket.io-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
39c90d4 to
d292954
Compare
d292954 to
a77f5f0
Compare
a77f5f0 to
e005747
Compare
e005747 to
e1a0d7a
Compare
e1a0d7a to
953412b
Compare
953412b to
ef71150
Compare
7d8d4b3 to
95a87f9
Compare
95a87f9 to
f875134
Compare
f875134 to
d6d6b5e
Compare
d6d6b5e to
26b3ce4
Compare
26b3ce4 to
763c376
Compare
763c376 to
6fc3b50
Compare
6fc3b50 to
2fe945e
Compare
3c75e2c to
58083a6
Compare
58083a6 to
93934b6
Compare
93934b6 to
fac16b1
Compare
fac16b1 to
94601f8
Compare
94601f8 to
1f71b7f
Compare
1f71b7f to
86f3b04
Compare
86f3b04 to
3a0eaf1
Compare
3a0eaf1 to
9e71b1b
Compare
9e71b1b to
83129d5
Compare
83129d5 to
6505a88
Compare
6505a88 to
adb5965
Compare
adb5965 to
5beab6c
Compare
5beab6c to
3e06de9
Compare
3e06de9 to
1da04aa
Compare
1da04aa to
9c0cd4a
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.4.8→^2.5.1GitHub Vulnerability Alerts
CVE-2020-28481
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
CVE-2024-38355
Impact
A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process.
Affected versions
4.6.2...latest3.0.0...4.6.1[email protected](at least)2.3.0...2.5.0[email protected]Patches
This issue is fixed by socketio/socket.io@15af22f, included in
[email protected](released in May 2023).The fix was backported in the 2.x branch today: socketio/socket.io@d30630b
Workarounds
As a workaround for the affected versions of the
socket.iopackage, you can attach a listener for the "error" event:For more information
If you have any questions or comments about this advisory:
Thanks a lot to Paul Taylor for the responsible disclosure.
References
Release Notes
socketio/socket.io (socket.io)
v2.5.1Compare Source
Bug Fixes
Links:
-~3.6.0(no change)~7.5.10v2.5.0Compare Source
The default value of the
maxHttpBufferSizeoption has been decreased from 100 MB to 1 MB, in order to prevent attacks by denial of service.Security advisory: GHSA-j4f2-536g-r55m
Bug Fixes
Links:
~3.6.0(diff)~7.4.2v2.4.1Compare Source
This release reverts the breaking change introduced in
2.4.0(f78a575).If you are using Socket.IO v2, you should explicitly allow/disallow cross-origin requests:
In any case, please consider upgrading to Socket.IO v3, where this security issue is now fixed (CORS is disabled by default).
Reverts
Links:
~3.5.0~7.4.2v2.4.0Compare Source
Related blog post: https://socket.io/blog/socket-io-2-4-0/
Features (from Engine.IO)
Bug Fixes
Previously, CORS was enabled by default, which meant that a Socket.IO server sent the necessary CORS headers (
Access-Control-Allow-xxx) to any domain. This will not be the case anymore, and you now have to explicitly enable it.Please note that you are not impacted if:
originsoption to restrict the list of allowed domainsThis commit also removes the support for '*' matchers and protocol-less URL:
To restore the previous behavior (please use with caution):
See also:
Thanks a lot to @ni8walk3r for the security report.
Links:
~3.5.0~7.4.2v2.3.0Compare Source
This release mainly contains a bump of the
engine.ioandwspackages, but no additional features.Links:
~3.4.0(diff: socketio/engine.io@3.3.1...3.4.2)^7.1.2(diff: websockets/ws@6.1.2...7.3.1)v2.2.0Compare Source
Features
Bug fixes
Links
~3.3.1(diff: socketio/engine.io@3.2.0...3.3.1)~6.1.0(diff: websockets/ws@3.3.1...6.1.2)v2.1.1Compare Source
Features
Bug fixes
(client) fire an error event on middleware failure for non-root namespace (socketio/socket.io-client#1202)
Links:
~3.2.0~3.3.1v2.1.0Compare Source
Features
Bug fixes
Important note⚠️ from Engine.IO 3.2.0 release
There are two non-breaking changes that are somehow quite important:
wswas reverted as the default wsEngine (socketio/engine.io#550), as there was several blocking issues withuws. You can still useuwsby runningnpm install uws --savein your project and using thewsEngineoption:pingTimeoutnow defaults to 5 seconds (instead of 60 seconds): socketio/engine.io#551Links:
~3.2.0(diff: socketio/engine.io@3.1.0...3.2.0)~3.3.1(diff: websockets/ws@2.3.1...3.3.1)v2.0.4Compare Source
Bug fixes
Links:
engine.io: -ws: -v2.0.3Compare Source
Bug fixes
Links:
engine.io: -ws: -v2.0.2Compare Source
Bug fixes
Links:
engine.io: -ws: -v2.0.1Compare Source
Bug fixes
- update path of client file (#2934)
Links:
engine.io: -ws: -v2.0.0Compare Source
This major release brings several performance improvements:
uws is now the default Websocket engine. It should bring significant improvement in performance (particularly in terms of memory consumption) (https://github.com/socketio/engine.io/releases/tag/2.0.0)
the Engine.IO and Socket.IO handshake packets were merged, reducing the number of roundtrips necessary to establish a connection. (#2833)
it is now possible to provide a custom parser according to the needs of your application (#2829). Please take a look at the example for more information.
Please note that this release is not backward-compatible, due to:
Please also note that if you are using a self-signed certificate,
rejectUnauthorizednow defaults totrue(socketio/engine.io-client#558).Finally, the API documentation is now in the repository (here), and the content of the website here. Do not hesitate if you see something wrong or missing!
The full list of changes:
localflag (#2816)clientsmethod in the API documentation (#2812)Besides, we are proud to announce that Socket.IO is now a part of open collective: https://opencollective.com/socketio. More on that later.
v1.7.4Compare Source
v1.7.3Compare Source
v1.7.2Compare Source
v1.7.1Compare Source
(following
socket.io-clientupdate)v1.7.0Compare Source
localflag (#2628)v1.6.0Compare Source
v1.5.1Compare Source
clientin test script (#2731)v1.5.0Compare Source
Configuration
📅 Schedule: Branch creation - "" in timezone Europe/Zurich, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.