Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4326-c9xj-r26f

Опубликовано: 10 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.

EPSS

Процентиль: 40%
0.00186
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-697

Связанные уязвимости

CVSS3: 4.6
nvd
больше 3 лет назад

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.

EPSS

Процентиль: 40%
0.00186
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-697