Missing Origin Validation in code-server by Coder
CVE-2023-26114
9.3CRITICAL
What is CVE-2023-26114?
Versions of code-server prior to 4.10.1 are susceptible to a vulnerability that lacks proper origin validation during WebSocket handshakes. This shortcoming may enable unauthorized users to connect to the code-server instance and potentially access sensitive data. It is essential for users of affected versions to update to the latest release to safeguard against this threat.
Affected Version(s)
code-server 0 < 4.10.1
