GHSA-37q6-576q-vgr7

Suggest an improvement
Source
https://github.com/advisories/GHSA-37q6-576q-vgr7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-37q6-576q-vgr7/GHSA-37q6-576q-vgr7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-37q6-576q-vgr7
Aliases
  • CVE-2018-14731
Published
2018-10-30T20:36:53Z
Modified
2023-11-08T03:59:56.925908Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Missing Origin Validation in parcel-bundler
Details

Versions of parcel-bundler before 1.10.0 are missing origin validation on the websocket server. This vulnerability allows a remote attacker to steal a developer's source code because the origin of requests to the websocket server that is used for Hot Module Replacement (HMR) are not validated.

Recommendation

Update to version 1.10.0 or later.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T20:54:24Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / parcel-bundler

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-37q6-576q-vgr7/GHSA-37q6-576q-vgr7.json"