QID 981130
QID 981130: Nodejs (npm) Security Update for webpack-dev-server (GHSA-cf66-xwfp-gvc4)
Versions of `webpack-dev-server` before 3.1.10 are missing origin validation on the websocket server. This vulnerability allows a remote attacker to steal a developer's source code because the origin of requests to the websocket server that is used for Hot Module Replacement (HMR) are not validated.
## Recommendation
For `webpack-dev-server` 2.x update to version 2.11.4 or later.
For `webpack-dev-server` 3.x update to version 3.1.11 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cf66-xwfp-gvc4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-cf66-xwfp-gvc4 -
github.com/advisories/GHSA-cf66-xwfp-gvc4
CVEs related to QID 981130
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cf66-xwfp-gvc4 | webpack-dev-server |
|