Gitpod
by Gitpod
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-32766 | Med | 0.33 | 6.1 | 0.01 | Jun 5, 2023 | Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three (vscode: vscode-insiders: jetbrains-gateway:). | ||
| CVE-2023-0957 | Hig | 0.00 | 8.2 | 0.00 | Mar 3, 2023 | An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is… | ||
| CVE-2021-35206 | Med | 0.00 | 6.1 | 0.01 | Jun 22, 2021 | Gitpod before 0.6.0 allows unvalidated redirects. |
- risk 0.33cvss 6.1epss 0.01
Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three (vscode: vscode-insiders: jetbrains-gateway:).
- risk 0.00cvss 8.2epss 0.00
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is…
- risk 0.00cvss 6.1epss 0.01
Gitpod before 0.6.0 allows unvalidated redirects.