Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket client. This allows attackers to surveil developers running Farm who visit their webpage and steal source code that is leaked by the WebSocket server.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
farm 安全漏洞
Vulnerability Description
farm是Farm开源的一个web构建工具。 farm 1.7.6之前版本存在安全漏洞,该漏洞源于WebSocket缺少来源验证,可能导致攻击者监控开发者并窃取源代码。
CVSS Information
N/A
Vulnerability Type
N/A