PT-2023-10141 · Lukehutch · Gribbit
Lukehutch
·
Published
2023-01-09
·
Updated
2024-05-17
·
CVE-2014-125071
CVSS v2.0
5.2
Medium
| Vector | AV:A/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
lukehutch Gribbit (affected versions not specified)
Description
A problematic issue was found in lukehutch Gribbit, affecting the
messageReceived function of the file src/gribbit/request/HttpRequestHandler.java. This issue leads to missing origin validation in websockets.Recommendations
Apply a patch to fix this issue, specifically the patch named
620418df247aebda3dd4be1dda10fe229ea505dd. As a temporary workaround, consider disabling the messageReceived function until a patch is available. Restrict access to the vulnerable HttpRequestHandler.java file to minimize the risk of exploitation.Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gribbit