Gitpod before 0.6.0 allows unvalidated redirects.
References
Link | Resource |
---|---|
https://github.com/gitpod-io/gitpod/blob/main/CHANGELOG.md | Release Notes Third Party Advisory |
https://github.com/gitpod-io/gitpod/commit/8ca431f86ae3a6f9a17afcfed51cdd065fcff1a5 | Patch Third Party Advisory |
https://github.com/gitpod-io/gitpod/compare/0.6.0-beta5...0.6.0 | Release Notes Third Party Advisory |
https://github.com/gitpod-io/gitpod/pull/2879 | Exploit Patch Third Party Advisory |
https://github.com/gitpod-io/gitpod/pull/2879#issuecomment-865662372 | Patch Third Party Advisory |
https://github.com/gitpod-io/gitpod/pull/4567 | Release Notes Third Party Advisory |
https://github.com/gitpod-io/gitpod/pull/4567/commits/f78b7d18e509e28e71b65bbd4dfd52c16ca57c18 | Patch Third Party Advisory |
https://www.gitpod.io/changelog | Release Notes Vendor Advisory |
Configurations
History
24 Jun 2021, 13:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-601 | |
CPE | cpe:2.3:a:gitpod:gitpod:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 5.8
v3 : 6.1 |
References | (MISC) https://github.com/gitpod-io/gitpod/pull/2879 - Exploit, Patch, Third Party Advisory | |
References | (MISC) https://www.gitpod.io/changelog - Release Notes, Vendor Advisory | |
References | (MISC) https://github.com/gitpod-io/gitpod/blob/main/CHANGELOG.md - Release Notes, Third Party Advisory | |
References | (MISC) https://github.com/gitpod-io/gitpod/pull/2879#issuecomment-865662372 - Patch, Third Party Advisory | |
References | (MISC) https://github.com/gitpod-io/gitpod/pull/4567/commits/f78b7d18e509e28e71b65bbd4dfd52c16ca57c18 - Patch, Third Party Advisory | |
References | (MISC) https://github.com/gitpod-io/gitpod/pull/4567 - Release Notes, Third Party Advisory | |
References | (MISC) https://github.com/gitpod-io/gitpod/commit/8ca431f86ae3a6f9a17afcfed51cdd065fcff1a5 - Patch, Third Party Advisory | |
References | (MISC) https://github.com/gitpod-io/gitpod/compare/0.6.0-beta5...0.6.0 - Release Notes, Third Party Advisory |
22 Jun 2021, 14:55
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-06-22 14:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-35206
Mitre link : CVE-2021-35206
CVE.ORG link : CVE-2021-35206
JSON object : View
Products Affected
gitpod
- gitpod
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')