Description
A WebSocket connection using ws:// sends data without transport encryption. The WebSocket constructor also converts http:// URLs to ws://, with the same risk. An attacker on the network path may intercept sensitive information or modify the exchanged messages.
Potential impact
- Network attackers may capture unencrypted credentials, session tokens or other sensitive data.
- Messages may be altered, compromising data integrity and trust in the service.
Remediation
- Use
wss://orhttps://URLs to encrypt WebSocket connections. TheWebSocketconstructor convertshttps://towss://. - Install and maintain TLS certificates correctly.
- Restrict cleartext connections to local loopback development environments such as
localhost,127.0.0.1or[::1]. Require encrypted connections in production.
Examples
Before
javascript
// Cleartext WebSocket connection
var ws = new WebSocket('ws://myapp.example.com/socket');
ws.onmessage = function(msg) {
console.log(msg.data);
}
After
javascript
// Use WebSocket over TLS (wss)
var ws = new WebSocket('wss://myapp.example.com/socket');
ws.onmessage = function(msg) {
console.log(msg.data);
}
Explanation:
- Before: A constructor URL beginning with
ws://orhttp://establishes a cleartext WebSocket connection that a network attacker may observe or alter. - After: A constructor URL beginning with
wss://orhttps://uses TLS to protect data in transit.