Authentication Bypass in console-io
Critical severity
GitHub Reviewed
Published
Feb 18, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Feb 18, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Affected versions of the
console-io
package do not configure the underlying websocket library to require authentication, resulting in an authentication bypass vulnerability. Asconsole-io
allows terminal access on the server via a web page, an authentication bypass is essentially remote code execution.Recommendation
Update to version 2.3.0 or later.
References