CRITICAL9.8
GHSA-6h8c-gw33-cjm2
DevSpace vulnerable to remote code execution
Quick fix
GHSA-6h8c-gw33-cjm2 — github.com/loft-sh/devspace: upgrade to the fixed version with the command below.
go get github.com/loft-sh/devspace@v4.14.0Details
The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket protocol. This leads to remote code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/loft-sh/devspace
Introduced in:
0Fixed in: 4.14.0Fix
go get github.com/loft-sh/devspace@v4.14.0