| |
Vulnerability CVE-2020-11020
Published: 2020-04-29
Description: |
Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication bypass in the extension system. The vulnerability allows any client to bypass checks put in place by server-side extensions, by appending extra segments to the message channel. It is patched in versions 1.0.4, 1.1.3 and 1.2.5. |
Type:
CWE-287 (Improper Authentication)
CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
7.5/10 |
6.4/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
Partial |
References: |
https://github.com/faye/faye/commit/65d297d341b607f3cb0b5fa6021a625a991cc30e
https://github.com/faye/faye/security/advisories/GHSA-qpg4-4w7w-2mq5
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|