Cleartext WebSocket transmission

Cleartext WebSocket transmission

Description

A WebSocket connection using ws:// sends data without transport encryption. The WebSocket constructor also converts http:// URLs to ws://, with the same risk. An attacker on the network path may intercept sensitive information or modify the exchanged messages.

Potential impact

  • Network attackers may capture unencrypted credentials, session tokens or other sensitive data.
  • Messages may be altered, compromising data integrity and trust in the service.

Remediation

  • Use wss:// or https:// URLs to encrypt WebSocket connections. The WebSocket constructor converts https:// to wss://.
  • Install and maintain TLS certificates correctly.
  • Restrict cleartext connections to local loopback development environments such as localhost, 127.0.0.1 or [::1]. Require encrypted connections in production.

Examples

Before

javascript
// Cleartext WebSocket connection
var ws = new WebSocket('ws://myapp.example.com/socket');
ws.onmessage = function(msg) {
    console.log(msg.data);
}

After

javascript
// Use WebSocket over TLS (wss)
var ws = new WebSocket('wss://myapp.example.com/socket');
ws.onmessage = function(msg) {
    console.log(msg.data);
}

Explanation:

  • Before: A constructor URL beginning with ws:// or http:// establishes a cleartext WebSocket connection that a network attacker may observe or alter.
  • After: A constructor URL beginning with wss:// or https:// uses TLS to protect data in transit.

References