CVE-2020-7693
MEDIUMsockjs < 0.3.20 - Denial of Service via Upgrade Header
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2020-7693. PoCs published by andsnw, thewindghost.
AI-analyzed exploit summary This repository contains a functional PoC for CVE-2020-7693, a DoS vulnerability in SockJS 0.3.19 and Meteor JS <1.10.2. The exploit sends crafted WebSocket upgrade requests to trigger an 'ERR_STREAM_WRITE_AFTER_END' error, crashing the target container.
Description
Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.
Exploits (2)
This repository contains a functional PoC for CVE-2020-7693, a DoS vulnerability in SockJS 0.3.19 and Meteor JS <1.10.2. The exploit sends crafted WebSocket upgrade requests to trigger an 'ERR_STREAM_WRITE_AFTER_END' error, crashing the target container.
This repository provides a functional proof-of-concept for CVE-2020-7693, demonstrating a denial-of-service (DoS) vulnerability in sockjs-node versions before 0.3.20. The exploit involves sending a crafted HTTP request with an 'Upgrade: websocket' header, which crashes the server.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L