Vulnerabilities > Devspace

DATE CVE VULNERABILITY TITLE RISK
2020-07-23 CVE-2020-15391 Missing Authentication for Critical Function vulnerability in Devspace 4.13.0
The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket protocol.
network
low complexity
devspace CWE-306
critical
9.8