Security Advisory

CVE-2018-20744

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-01-28 08:00:00
Last updated 2024-08-05 12:12:28
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.