Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20745

Опубликовано: 28 янв. 2019
Источник: debian

Описание

Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
yiiitppackage

Связанные уязвимости

CVSS3: 5.9
nvd
около 7 лет назад

Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.

CVSS3: 5.9
github
больше 3 лет назад

Yii Incorrectly Implements CORS