GHSA-cf66-xwfp-gvc4
Dashboard / Vulnerabilities / GHSA-cf66-xwfp-gvc4
Summary: Missing Origin Validation in webpack-dev-server
Details: Versions of `webpack-dev-server` before 3.1.10 are missing origin validation on the websocket server. This vulnerability allows a remote attacker to steal a developer's source code because the origin of requests to the websocket server that is used for Hot Module Replacement (HMR) are not validated. ## Recommendation For `webpack-dev-server` update to version 3.1.11 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-14732, https://github.com/webpack/webpack-dev-server/issues/1445, https://github.com/webpack/webpack-dev-server/issues/1620, https://github.com/webpack/webpack-dev-server/commit/f18e5adf123221a1015be63e1ca2491ca45b8d10, https://github.com/webpack/webpack-dev-server, https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md#3111-2018-12-21, https://www.npmjs.com/advisories/725
Affected packages
Package
Name: webpack-dev-server
Purl: pkg:npm/webpack-dev-server
Affected ranges
Type: SEMVER
Events:
