Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjm9-gq46-wc5j

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests.

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests.

EPSS

Процентиль: 4%
0.00019
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 месяцев назад

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests.

EPSS

Процентиль: 4%
0.00019
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-346