Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59qh-fmm7-3g9q

Опубликовано: 11 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

Rembg CORS misconfiguration

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credentials is set to True, which would allow any website to send authenticated cross site requests.

Пакеты

Наименование

rembg

pip
Затронутые версииВерсия исправления

<= 2.0.57

Отсутствует

EPSS

Процентиль: 11%
0.00038
Низкий

8.7 High

CVSS4

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 6.5
nvd
11 месяцев назад

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credentials is set to True, which would allow any website to send authenticated cross site requests.

EPSS

Процентиль: 11%
0.00038
Низкий

8.7 High

CVSS4

Дефекты

CWE-346