OpenTree-Education / rhizone-lms

A learning management system focused on self-reflection.
https://rhi.zone
BSD 3-Clause Clear License
14 stars 7 forks source link

High-impact security vulnerability: Uncaught exception in engine.io #440

Closed seidior closed 1 year ago

seidior commented 1 year ago

Description

Dependabot has shared there's a high-impact security vulnerability in one of the packages we use, socket.io.

Proposed solution

Upgrade relevant packages and fix any relevant code.

Details and resources

The relevant CVE is CVE-2022-41940.

Checklist