VDB
Sign up
CRITICAL9.8

GHSA-6h8c-gw33-cjm2

DevSpace vulnerable to remote code execution

Quick fix

GHSA-6h8c-gw33-cjm2 — github.com/loft-sh/devspace: upgrade to the fixed version with the command below.

go get github.com/loft-sh/devspace@v4.14.0

Details

The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket protocol. This leads to remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/loft-sh/devspace
Introduced in: 0Fixed in: 4.14.0
Fixgo get github.com/loft-sh/devspace@v4.14.0

References