CVE-2023-0957 is a critical Cross-Site WebSocket Hijacking (CSWSH) vulnerability affecting Gitpod versions prior to release-2022.11.2.16. This flaw allows attackers to establish WebSocket connections to the Gitpod JSONRPC server using a victim's credentials due to insufficient Origin header restrictions. With a CVSS score of 9.6 (CRITICAL), the vulnerability has a network attack vector, low attack complexity, and requires user interaction, potentially leading to full workspace takeover and data extraction. There is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, though it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022.11.2CPE matchmatch criteria | cpe:2.3:a:gitpod:gitpod:*:*:*:*:*:*:*:* | ||
>= 0, < 2022.11.2CPE match | cpe:2.3:a:gitpod:gitpod:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.