Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-27786

Опубликовано: 09 июн. 2022
Источник: nvd
CVSS3: 4.6
CVSS3: 9.8
CVSS2: 6.8
EPSS Низкий

Описание

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:hcltech:onetest_server:10.0:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:onetest_server:10.1:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:onetest_server:10.2:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00186
Низкий

4.6 Medium

CVSS3

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-942
CWE-697

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.

EPSS

Процентиль: 40%
0.00186
Низкий

4.6 Medium

CVSS3

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-942
CWE-697