A vulnerability was found in lukehutch Gribbit. It has been classified as problematic. Affected is the function messageReceived of the file src/gribbit/request/HttpRequestHandler.java. The manipulation leads to missing origin validation in websockets. The name of the patch is 620418df247aebda3dd4be1dda10fe229ea505dd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217716.
The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://vuldb.com/?id.217716 | vdb entry third party advisory technical description |
https://vuldb.com/?ctiid.217716 | third party advisory permissions required signature |
https://github.com/lukehutch/gribbit/commit/620418df247aebda3dd4be1dda10fe229ea505dd | third party advisory patch |