Browse Security Advisories
High Security Advisories for code-server for https://github.com/coder/code-server Clear Filters
High
3 months ago
code-server's session cookie can be extracted by having user visit specially crafted proxy URL
npm
code-server
Filter by Severity
Filter by Ecosystem
maven
2,233
pypi
1,791
npm
1,631
packagist
1,447
go
1,007
nuget
938
cargo
389
rubygems
307
swift
18
actions
17
hex
10
pub
5
Filter by Package
Microsoft.ChakraCore
234
tensorflow
122
tensorflow-gpu
119
tensorflow-cpu
115
magento/community-edition
80
moodle/moodle
61
org.jenkins-ci.main:jenkins-core
56
Django
49
com.fasterxml.jackson.core:jackson-databind
43
typo3/cms
42
dolibarr/dolibarr
34
org.apache.tomcat:tomcat
33
drupal/core
33
Plone
33
librenms/librenms
32
pimcore/pimcore
30
mlflow
30
drupal/drupal
29
salt
29
typo3/cms-core
29
apache-airflow
29
github.com/rancher/rancher
28
phpmyadmin/phpmyadmin
28
microweber/microweber
27
nokogiri
26
magento/project-community-edition
24
ansible
24
org.apache.struts:struts2-core
24
opencv-python
23
opencv-contrib-python
23
com.thoughtworks.xstream:xstream
22
symfony/symfony
22
com.liferay.portal:release.portal.bom
22
Pillow
21
com.jfinal:jfinal
21
org.jenkins-ci.plugins:script-security
20
matrix-synapse
20
org.apache.tomcat.embed:tomcat-embed-core
20
django
20
thorsten/phpmyfaq
20
com.liferay.portal:release.dxp.bom
19
rdiffweb
17
pocketmine/pocketmine-mp
17
gradio
17
openssl-src
17
Microsoft.AspNetCore.App.Runtime.win-x64
17
github.com/hashicorp/vault
17
Microsoft.AspNetCore.App.Runtime.win-x86
17
github.com/grafana/grafana
17
io.undertow:undertow-core
16
pillow
16
parse-server
16
getgrav/grav
16
Microsoft.AspNetCore.App.Runtime.win-arm
16
keystone
15
github.com/hashicorp/consul
15
nilsteampassnet/teampass
15
org.xwiki.platform:xwiki-platform-oldcore
15
Microsoft.AspNetCore.App.Runtime.win-arm64
15
open-webui
15
Microsoft.AspNetCore.App.Runtime.linux-x64
14
Microsoft.AspNetCore.App.Runtime.osx-x64
14
github.com/usememos/memos
14
Microsoft.AspNetCore.App.Runtime.linux-musl-x64
14
centreon/centreon
14
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
14
Microsoft.AspNetCore.App.Runtime.linux-arm64
14
Microsoft.AspNetCore.App.Runtime.linux-arm
14
org.keycloak:keycloak-core
14
craftcms/cms
14
shopware/platform
14
Microsoft.NetCore.App.Runtime.win-x86
14
Microsoft.NetCore.App.Runtime.win-x64
14
vyper
14
Microsoft.NetCore.App.Runtime.win-arm64
14
net.mingsoft:ms-mcms
14
Microsoft.NetCore.App.Runtime.win-arm
14
apache-superset
13
org.keycloak:keycloak-services
13
rubygems-update
13
electron
13
silverstripe/framework
13
golang.org/x/net
13
mautic/core
13
org.apache.solr:solr-core
13
mindsdb
13
phpoffice/phpexcel
12
activerecord
12
org.apache.openmeetings:openmeetings-parent
12
baserproject/basercms
12
shopware/core
12
cockpit-hq/cockpit
11
intelliants/subrion
11
froxlor/froxlor
11
next
11
org.keycloak:keycloak-parent
11
phpoffice/phpspreadsheet
11
github.com/hashicorp/nomad
11
actionpack
11
github.com/nats-io/nats-server/v2
11
github.com/zitadel/zitadel
11
directus
11
gogs.io/gogs
11
Microsoft.AspNetCore.App.Runtime.linux-musl-arm
10
github.com/ollama/ollama
10
org.springframework.security:spring-security-core
10
laravel/framework
10
surrealdb
10
deno
10
github.com/traefik/traefik/v2
10
openmage/magento-lts
10
funadmin/funadmin
10
github.com/argoproj/argo-cd
10
nova
10
snipe/snipe-it
10
k8s.io/kubernetes
10
Microsoft.NetCore.App.Runtime.linux-arm64
9
github.com/ethereum/go-ethereum
9
cobbler
9
neutron
9
org.apache.struts.xwork:xwork-core
9
org.bouncycastle:bcprov-jdk14
9
Microsoft.NetCore.App.Runtime.osx-arm64
9
Microsoft.NetCore.App.Runtime.osx-x64
9
Microsoft.NetCore.App.Runtime.linux-musl-arm
9
org.apache.hadoop:hadoop-main
9
lollms
9
Microsoft.NetCore.App.Runtime.linux-arm
9
rusqlite
9
org.apache.geode:geode-core
9
litellm
9
ckb
9
aim
9
Microsoft.NetCore.App.Runtime.linux-x64
9
Microsoft.NetCore.App.Runtime.linux-musl-x64
9
mercurial
9
Microsoft.NetCore.App.Runtime.linux-musl-arm64
9
org.apache.nifi:nifi
9
org.cloudfoundry.identity:cloudfoundry-identity-server
9
h2o
9
zendframework/zendframework1
9
yeswiki/yeswiki
8
moin
8
org.apache.tomcat:tomcat-catalina
8
Microsoft.AspNetCore.App.Runtime.osx-arm64
8
org.jenkins-ci.plugins.workflow:workflow-cps
8
Microsoft.NETCore.App.Runtime.win-x64
8
org.bouncycastle:bcprov-jdk15
8
github.com/docker/docker
8
github.com/sylabs/singularity
8
org.apache.tomcat:tomcat-coyote
8
org.craftercms:crafter-studio
8
smarty/smarty
8
github.com/argoproj/argo-cd/v2
8
org.eclipse.jetty:jetty-server
8
Microsoft.NETCore.App.Runtime.win-x86
8
Microsoft.NETCore.App.Runtime.win-arm64
8
phpbb/phpbb
8
plone
8
ai.h2o:h2o-core
8
cryptography
8
october/system
8
composer/composer
8
rack
8
k8s.io/ingress-nginx
7
strapi
7
flowise
7
phpmailer/phpmailer
7
apollo-router
7
OPCFoundation.NetStandard.Opc.Ua.Core
7
symfony/security-http
7
org.springframework:spring-core
7
cakephp/cakephp
7
org.apache.inlong:manager-pojo
7
opencv-contrib-python-headless
7
@strapi/strapi
7
opencv-python-headless
7
contao/core-bundle
7
mantisbt/mantisbt
7
pyload-ng
7
symfony/security
7
com.xuxueli:xxl-job
7
github.com/filebrowser/filebrowser/v2
7
DotNetNuke.Core
7
zendframework/zendframework
7
magento/core
7
org.elasticsearch:elasticsearch
7
cn.hutool:hutool-core
7
tar
7
ryu
7
org.jenkins-ci.plugins.workflow:workflow-cps-global-lib
7
golang.org/x/crypto
7
codeigniter4/framework
7
github.com/kyverno/kyverno
6
ezsystems/ezpublish-kernel
6
prestashop/prestashop
6
mobsf
6
nautobot
6
org.apache.dolphinscheduler:dolphinscheduler
6
handlebars
6