Gitpod before 0.6.0 allows unvalidated redirects.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://github.com/gitpod-io/gitpod/pull/2879 | patch third party advisory exploit |
https://github.com/gitpod-io/gitpod/pull/2879#issuecomment-865662372 | third party advisory patch |
https://github.com/gitpod-io/gitpod/pull/4567 | third party advisory release notes |
https://www.gitpod.io/changelog | release notes vendor advisory |
https://github.com/gitpod-io/gitpod/blob/main/CHANGELOG.md | third party advisory release notes |
https://github.com/gitpod-io/gitpod/commit/8ca431f86ae3a6f9a17afcfed51cdd065fcff1a5 | third party advisory patch |
https://github.com/gitpod-io/gitpod/compare/0.6.0-beta5...0.6.0 | third party advisory release notes |
https://github.com/gitpod-io/gitpod/pull/4567/commits/f78b7d18e509e28e71b65bbd4dfd52c16ca57c18 | third party advisory patch |