VYPR

CWE-1385

Missing Origin Validation in WebSockets

VariantIncomplete

Description

The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (42)

page 3 of 3
  • CVE-2023-2848HigSep 14, 2023
    risk 0.00cvss 8.0epss 0.00

    Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a missing header validation.

  • CVE-2023-0957HigMar 3, 2023
    risk 0.00cvss 8.2epss 0.00

    An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is…