NA

CVE-2023-26114

Published: 23/03/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.3 | Impact Score: 5.8 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Versions of the package code-server prior to 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

Vulnerable Product Search on Vulmon Subscribe to Product

coder code-server