Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mchx-7j67-8mcf

Опубликовано: 22 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

Casdoor CORS misconfiguration (GHSL-2024-035)

Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor as the logged in user. Due to the a logic error in checking only for a prefix when authenticating the Origin header, any domain can create a valid subdomain with a valid subdomain prefix (Ex: localhost.example.com), allowing the website to make requests to Casdoor as the current signed-in user.

Пакеты

Наименование

github.com/casdoor/casdoor

go
Затронутые версииВерсия исправления

<= 1.557.0

Отсутствует

EPSS

Процентиль: 79%
0.01286
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-942

Связанные уязвимости

CVSS3: 8.1
nvd
больше 1 года назад

Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor as the logged in user. Due to the a logic error in checking only for a prefix when authenticating the Origin header, any domain can create a valid subdomain with a valid subdomain prefix (Ex: localhost.example.com), allowing the website to make requests to Casdoor as the current signed-in user.

EPSS

Процентиль: 79%
0.01286
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-942