Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6566-9526-52v6

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Exposure of Sensitive Information to an Unauthorized Actor in Concord

An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potentially unsafe dependency on Origin headers, and are not configurable. This allows remote attackers to discover host information, nodes, API metadata, and references to usernames via api/v1/apikey.

Пакеты

Наименование

com.walmartlabs.concord:concord-common

maven
Затронутые версииВерсия исправления

< 1.44.0

1.44.0

EPSS

Процентиль: 72%
0.00723
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
почти 6 лет назад

An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potentially unsafe dependency on Origin headers, and are not configurable. This allows remote attackers to discover host information, nodes, API metadata, and references to usernames via api/v1/apikey.

EPSS

Процентиль: 72%
0.00723
Низкий

7.5 High

CVSS3

Дефекты

CWE-200