Beveiligingsadvies

CVE-2018-20744

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-01-28 08:00:00
Laatst bijgewerkt 2024-08-05 12:12:28
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.