GHSA-6h8c-gw33-cjm2
CRITICALCVE-2020-15391The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket protocol. This leads to remote code execution.
- Affected
- <= 4.13.0
- Fixed in
- 4.14.0
- Weakness
- CWE-287
- Published
- 2022-05-24
- Source
- github