← Back

Gitpod

gitpod

Vendor: Gitpod • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitpod
1Gitpod
Jun 17, 2026
Jun 5, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three (vscode: vscode-insiders: jetbrains-gateway:).
1Gitpod
1Gitpod
Jun 17, 2026
Mar 3, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server u...Show more
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is not restricted. This can lead to the extraction of data from workspaces, to a full takeover of the workspace.Show less
1Gitpod
1Gitpod
Jun 17, 2026
Jun 22, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Gitpod before 0.6.0 allows unvalidated redirects.