Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-57111

Опубликовано: 09 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:helix:*:*:*:*:*:*:*:*
Версия до 2.0.1 (исключая)

EPSS

Процентиль: 19%
0.00269
Низкий

7.5 High

CVSS3

Дефекты

CWE-1385

Связанные уязвимости

CVSS3: 7.5
github
22 дня назад

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue.

EPSS

Процентиль: 19%
0.00269
Низкий

7.5 High

CVSS3

Дефекты

CWE-1385