{"id":"CVE-2020-15391","details":"The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket protocol. This leads to remote code execution.","aliases":["GHSA-6h8c-gw33-cjm2"],"modified":"2026-07-08T14:58:58.369417Z","published":"2020-07-23T20:15:11.630Z","references":[{"type":"ADVISORY","url":"https://github.com/devspace-cloud/devspace/tags"},{"type":"FIX","url":"https://github.com/devspace-cloud/devspace/releases/tag/v4.14.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/devspace-sh/devspace","events":[{"introduced":"c29f25a287002e41d2208301763268089551ec95"},{"last_affected":"c29f25a287002e41d2208301763268089551ec95"},{"fixed":"c62fc7e1531aadafaecd418cd6f2c260934244e6"}],"database_specific":{"extracted_events":[{"introduced":"4.13.0"},{"last_affected":"4.13.0"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:devspace:devspace:4.13.0:*:*:*:*:*:*:*"}}],"versions":["4.13.0","v4.14.0-beta.1","v4.13.1","v4.13.0-beta.1","v4.13.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15391.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}