Описание
The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket protocol. This leads to remote code execution.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:devspace:devspace:4.13.0:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02381
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-306
Связанные уязвимости
EPSS
Процентиль: 85%
0.02381
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-306