Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. Exploitation requires an existing low-privilege role with access to the target workspace. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. No known workarounds are available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.29.17CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* | ||
>= 2.30.0, < 2.32.7CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* | ||
>= 2.33.0, < 2.33.8CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* | ||
>= 2.34.0, < 2.34.2CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.