Security Control Framework
A brief look at Gitpod, two bugs, and a quick fix

A brief look at Gitpod, two bugs, and a quick fix

7/8/2021 · Joern Schneeweisz

What this post added

This post details the discovery and reporting of two critical vulnerabilities in Gitpod: 1. Cross-origin WebSocket access, allowing an attacker to potentially steal OAuth tokens by serving malicious JavaScript on an exposed Gitpod workspace port. 2. The ability to log in as any account by leveraging custom integrations with self-managed GitLab instances and spoofing email addresses. Both issues were reported to Gitpod and fixed within hours.

Read the original post ↗