Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-20146

Опубликовано: 27 дек. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 9.8

Описание

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

code not present
esm-apps/bionic

needed

esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/xenial

needed

focal

not-affected

code not present
jammy

not-affected

code not present
kinetic

ignored

end of life, was needs-triage

Показывать по

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
около 3 лет назад

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

CVSS3: 9.8
nvd
около 3 лет назад

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

CVSS3: 9.8
debian
около 3 лет назад

Usage of the CORS handler may apply improper CORS headers, allowing th ...

CVSS3: 9.8
github
около 3 лет назад

gorilla/handlers may allow requester to bypass expected behavior of the Same Origin Policy

9.8 Critical

CVSS3