漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
Vulnerability Description
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website a developer visits while the dev server is running can trigger these endpoints cross-origin with no interaction beyond the visit. An attacker can open an arbitrary existing local file in the developer's editor, including files outside the project root, and repeated requests can spawn editor processes and force recompilations that degrade the developer's machine. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: none.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
webpack-dev-server 跨站请求伪造漏洞
Vulnerability Description
webpack-dev-server webpack-dev-server是webpack-dev-server的开发服务器。 webpack-dev-server 5.2.5及之前版本存在安全漏洞,该漏洞源于暴露内部开发者端点,未验证请求来源,可能允许攻击者跨域触发,打开开发者编辑器内的任意本地文件,包括项目根目录外的文件,并通过重复请求生成编辑器进程和强制重新编译,从而降低开发者机器的性能。
CVSS Information
N/A
Vulnerability Type
N/A