Aggregates CVE and security vulnerability intelligence across all gitpod-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk cross-site scripting and vendor risk open redirect and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-32766 | Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three (vscode: vscode-insiders: jetbrains-gateway:). | [email protected] | 6.1 | 0.17% | 2023-06-05 | 2025-01-31 |
| CVE-2023-0957 | An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is not restricted. This can lead to the extraction of data from workspaces, to a full takeover of the workspace. | [email protected] | 8.2 | 0.44% | 2023-03-03 | 2024-11-21 |
| CVE-2021-35206 | Gitpod before 0.6.0 allows unvalidated redirects. | [email protected] | 6.1 | 0.51% | 2021-06-22 | 2024-11-21 |