CVE-2023-26114
Summary
| CVE | CVE-2023-26114 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-23 05:15:00 UTC |
| Updated | 2023-11-07 04:09:00 UTC |
| Description | Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance. |
Risk And Classification
Problem Types: CWE-346
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Coder | Code-server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Add origin checks to web sockets (#6048) · coder/code-server@d477972 · GitHub | MISC | github.com | |
| Missing Origin Validation in WebSockets in code-server | CVE-2023-26114 | Snyk | MISC | security.snyk.io | |
| Release v4.10.1 · coder/code-server · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.