Логотип exploitDog
bind:CVE-2019-9580
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-9580

Количество 2

Количество 2

nvd логотип

CVE-2019-9580

почти 7 лет назад

In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-v3xf-5q99-hxf5

больше 3 лет назад

In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.

CVSS3: 6.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-9580

In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.

CVSS3: 6.1
10%
Средний
почти 7 лет назад
github логотип
GHSA-v3xf-5q99-hxf5

In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.

CVSS3: 6.1
10%
Средний
больше 3 лет назад

Уязвимостей на страницу