Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4v9f-r55g-g6hc

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.6

Описание

Prefect CORS (Cross-Origin Resource Sharing) misconfiguration

A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect prior to version 3.0.3 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to the database, resulting in potential data leaks, loss of confidentiality, service disruption, and data integrity risks.

Пакеты

Наименование

prefect

pip
Затронутые версииВерсия исправления

>= 3.0.0rc1, < 3.0.3

3.0.3

Наименование

prefect

pip
Затронутые версииВерсия исправления

< 2.20.17

2.20.17

EPSS

Процентиль: 21%
0.00066
Низкий

7.6 High

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 7.6
nvd
11 месяцев назад

A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to the database, resulting in potential data leaks, loss of confidentiality, service disruption, and data integrity risks.

EPSS

Процентиль: 21%
0.00066
Низкий

7.6 High

CVSS3

Дефекты

CWE-346