Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-96g3-r54f-fx2v

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests.

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests.

EPSS

Процентиль: 4%
0.00019
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 месяцев назад

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests. NOTE: the Supplier disputes this, providing the rationale of "sending requests with credentials does not provide any additional access compared to unauthenticated requests."

EPSS

Процентиль: 4%
0.00019
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-346