CVE-2023-26114
Published Mar 23, 2023
Last updated a year ago
Overview
- Description
- Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.
- Source
- report@snyk.io
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.3
- Impact score
- 5.8
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
- Severity
- CRITICAL
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:coder:code-server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E36A6CC6-DD16-4EC8-8E13-C8A4C2836284", "versionEndExcluding": "4.10.1" } ], "operator": "OR" } ] } ]