Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-20146

Опубликовано: 27 дек. 2022
Источник: redhat
CVSS3: 7

Описание

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

A flaw was found in Gorilla. Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-registry-rhel8Not affected
OpenShift API for Data Protectionoadp/oadp-registry-rhel8Not affected
OpenShift API for Data Protectionoadp/oadp-velero-plugin-rhel8Not affected
OpenShift Developer Tools and ServiceshelmNot affected
OpenShift Developer Tools and Servicesjenkins-operator-containerNot affected
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Not affected
OpenShift Serverlessopenshift-serverless-1/ingress-rhel8-operatorNot affected
OpenShift Serverlessopenshift-serverless-1-knative-client-plugin-event-sender-rhel8-containerNot affected
Red Hat 3scale API Management Platform 23scale-operator-containerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-942
https://bugzilla.redhat.com/show_bug.cgi?id=2158262gorilla: Usage of the CORS handler may apply improper CORS headers

7 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 3 лет назад

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

CVSS3: 9.8
nvd
около 3 лет назад

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

CVSS3: 9.8
debian
около 3 лет назад

Usage of the CORS handler may apply improper CORS headers, allowing th ...

CVSS3: 9.8
github
около 3 лет назад

gorilla/handlers may allow requester to bypass expected behavior of the Same Origin Policy

7 High

CVSS3