Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
HIGH 7.5 npm

Missing Origin Validation in webpack-dev-server

GHSA-cf66-xwfp-gvc4 · CVE-2018-14732

Published · Modified

Description

Versions of webpack-dev-server before 3.1.10 are missing origin validation on the websocket server. This vulnerability allows a remote attacker to steal a developer's source code because the origin of requests to the websocket server that is used for Hot Module Replacement (HMR) are not validated.

Recommendation

For webpack-dev-server update to version 3.1.11 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes