CVE-2018-14732 | webpack-dev-server up to 3.1.5 WebSocket Server lib/Server.js Request input validation (Nessus ID 264716)
A vulnerability described as critical has been identified in webpack-dev-server up to 3.1.5. Impacted is an unknown function in the library lib/Server.js of the component WebSocket Server. Executing manipulation as part of Request can lead to improper input validation.
This vulnerability is registered as CVE-2018-14732. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.