Количество 2
Количество 2
CVE-2023-26114
почти 3 года назад
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.
CVSS3: 8.2
EPSS: Низкий
GHSA-frjg-g767-7363
почти 3 года назад
code-server vulnerable to Missing Origin Validation in WebSockets
CVSS3: 9.3
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-26114 Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance. | CVSS3: 8.2 | 0% Низкий | почти 3 года назад | |
GHSA-frjg-g767-7363 code-server vulnerable to Missing Origin Validation in WebSockets | CVSS3: 9.3 | 0% Низкий | почти 3 года назад |
Уязвимостей на страницу
20