Researchers discovered a vulnerability in Gitpod that could have allowed attackers to perform account takeover and remote code execution. Cloud-based development environments introduce unique security risks that organizations should assess. The vulnerability found by the researchers was related to cross-site WebSocket
•2m read time• From csoonline.com
Table of contents
The commonly misunderstood cross-site WebSocket hijackingHow researchers exploited the now-fixed Gitpod flawSort: