Описание
An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random origins by accepting the arbitrary 'Origin: example.com' header and responding with 200 OK and a wildcard 'Access-Control-Allow-Origin: *' header.
Ссылки
- ExploitThird Party Advisory
- Vendor Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:damstratechnology:smart_asset:2020.7:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00445
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-346
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random origins by accepting the arbitrary 'Origin: example.com' header and responding with 200 OK and a wildcard 'Access-Control-Allow-Origin: *' header.
EPSS
Процентиль: 63%
0.00445
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-346