添加链接
link管理
链接快照平台
  • 输入网页链接,自动生成快照
  • 标签化管理网页链接

Versions of webpack-dev-server before 3.1.10 are missing origin validation on the websocket server. This vulnerability allows a remote attacker to steal a developer's source code because the origin of requests to the websocket server that is used for Hot Module Replacement (HMR) are not validated.

Recommendation

For webpack-dev-server update to version 3.1.11 or later.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2018-14732
  • webpack/webpack-dev-server@ f18e5ad
  • https://www.npmjs.com/advisories/725
  • webpack/webpack-dev-server#1445
  • https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md#3111-2018-12-21
  • webpack/webpack-dev-server#1620
  •