Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-gqx9-h3w2-fprg: Gitpod vulnerable to Cross-site Scripting

Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three (vscode: vscode-insiders: jetbrains-gateway:).

ghsa
#xss#git

Gitpod vulnerable to Cross-site Scripting

Moderate severity GitHub Reviewed Published Jun 5, 2023 to the GitHub Advisory Database • Updated Jun 6, 2023

Related news

CVE-2023-32766: Release 2022.11.3 · gitpod-io/gitpod

Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three (vscode: vscode-insiders: jetbrains-gateway:).