Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-10549

Опубликовано: 31 мая 2018
Источник: nvd
CVSS3: 4.4
CVSS2: 2.1
EPSS Низкий

Описание

Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration where the value of the origin header is reflected as the value for the Access-Control-Allow-Origin header. This would allow an attacker to make AJAX requests to vulnerable hosts through cross site scripting or a malicious HTML Document, effectively bypassing the Same Origin Policy. Note that this is only an issue when allRoutes is set to true and origin is set to * or left commented out in the sails CORS config file. The problem can be compounded when the cors credentials setting is not provided. At that point authenticated cross domain requests are possible.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sailsjs:sails:*:*:*:*:*:node.js:*:*
Версия до 0.12.7 (включая)

EPSS

Процентиль: 49%
0.00254
Низкий

4.4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-284
CWE-79

Связанные уязвимости

github
почти 7 лет назад

Sails before 0.12.7 vulnerable to Broken CORS

EPSS

Процентиль: 49%
0.00254
Низкий

4.4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-284
CWE-79