Логотип exploitDog
bind:CVE-2023-26114
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-26114

Количество 2

Количество 2

nvd логотип

CVE-2023-26114

почти 3 года назад

Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-frjg-g767-7363

почти 3 года назад

code-server vulnerable to Missing Origin Validation in WebSockets

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-26114

Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

CVSS3: 8.2
0%
Низкий
почти 3 года назад
github логотип
GHSA-frjg-g767-7363

code-server vulnerable to Missing Origin Validation in WebSockets

CVSS3: 9.3
0%
Низкий
почти 3 года назад

Уязвимостей на страницу