Versions of webpack-dev-server
before 3.1.10 are missing origin validation on the websocket server. This vulnerability allows a remote attacker to steal a developer's source code because the origin of requests to the websocket server that is used for Hot Module Replacement (HMR) are not validated.
Recommendation
For webpack-dev-server
update to version 3.1.11 or later.
- https://nvd.nist.gov/vuln/detail/CVE-2018-14732
- https://github.com/webpack/webpack-dev-server/commit/f18e5adf123221a1015be63e1ca2491ca45b8d10
- https://www.npmjs.com/advisories/725
- https://github.com/webpack/webpack-dev-server/issues/1445
- https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md#3111-2018-12-21
- https://github.com/webpack/webpack-dev-server/issues/1620
- https://github.com/advisories/GHSA-cf66-xwfp-gvc4