目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-55750— gitpod 安全漏洞

CVSS 6.5 · Medium EPSS 0.33% · P25
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-55750 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Gitpod Classic Affected by Bitbucket OAuth Token Exposure via Redirect Fragment
来源: CVE Program / CVE List V5
Vulnerability Description
Gitpod is a developer platform for cloud development environments. In versions before main-gha.33628 for both Gitpod Classic and Gitpod Classic Enterprise, OAuth integration with Bitbucket in certain conditions allowed a crafted link to expose a valid Bitbucket access token via the URL fragment when clicked by an authenticated user. This resulted from how Bitbucket returned tokens and how Gitpod handled the redirect flow. The issue was limited to Bitbucket (GitHub and GitLab integrations were not affected), required user interaction, and has been mitigated through redirect handling and OAuth logic hardening. The issue was resolved in main-gha.33628 and later. There are no workarounds.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
通过发送数据的信息暴露
来源: CVE Program / CVE List V5
Vulnerability Title
gitpod 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
gitpod是gitpod开源的一款基于云的集成开发环境。 gitpod main-gha.33628之前版本存在安全漏洞,该漏洞源于Bitbucket OAuth集成处理不当,可能导致访问令牌泄露。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
gitpod-iogitpod Gitpod Classic < main-gha.33628 -

二、漏洞 CVE-2025-55750 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-55750 的情报信息

登录查看更多情报信息。

CVE-2025-55750 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-55750

暂无评论


发表评论