Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0957

Опубликовано: 03 мар. 2023
Источник: nvd
CVSS3: 8.2
CVSS3: 9.6
EPSS Низкий

Описание

An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is not restricted. This can lead to the extraction of data from workspaces, to a full takeover of the workspace.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gitpod:gitpod:*:*:*:*:*:*:*:*
Версия до 2022.11.2 (исключая)

EPSS

Процентиль: 50%
0.00265
Низкий

8.2 High

CVSS3

9.6 Critical

CVSS3

Дефекты

CWE-1385
CWE-346

Связанные уязвимости

CVSS3: 9.6
github
больше 2 лет назад

An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is not restricted. This can lead to the extraction of data from workspaces, to a full takeover of the workspace.

EPSS

Процентиль: 50%
0.00265
Низкий

8.2 High

CVSS3

9.6 Critical

CVSS3

Дефекты

CWE-1385
CWE-346