CVE-2019-13611

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
16/07/2019
Last modified:
22/07/2019

Description

An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python-engineio_project:python-engineio:*:*:*:*:*:*:*:* 3.8.2 (including)


References to Advisories, Solutions, and Tools