{"id":"CVE-2018-14730","aliases":[],"url":"https://o3.security/vulnerability/CVE-2018-14730","summary":"Missing Origin Validation in browserify-hmr","details":"Versions of `browserify-hmr` prior to 0.4.0 are missing origin validation on the websocket server. \n\nThis vulnerability allows a remote attacker to steal a developer's source code because the origin of requests to the websocket server that is used for Hot Module Replacement (HMR) are not validated.\n\n\n## Recommendation\n\nUpgrade to version 0.4.0 or later.","published":"2020-09-01T21:18:20Z","modified":"2023-11-08T03:59:56.864154Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"browserify-hmr","fixedVersion":"0.4.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-14730"},{"type":"WEB","url":"https://github.com/AgentME/browserify-hmr/issues/41"},{"type":"WEB","url":"https://blog.cal1.cn/post/Sniffing%20Codes%20in%20Hot%20Module%20Reloading%20Messages"},{"type":"WEB","url":"https://blog.cal1.cn/post/Sniffing%20Codes%20in%20Hot%20Module%20Reloading%20Messages)"},{"type":"PACKAGE","url":"https://github.com/AgentME/browserify-hmr"},{"type":"WEB","url":"https://www.npmjs.com/advisories/726"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:59:56.864154Z"}}