Логотип exploitDog
bind:CVE-2014-7193
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-7193

Количество 2

Количество 2

nvd логотип

CVE-2014-7193

около 11 лет назад

The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which allows remote attackers to obtain sensitive information, and potentially obtain the ability to spoof requests to non-CORS routes, via a crafted web site that is visited by an application consumer.

CVSS2: 5.8
EPSS: Низкий
github логотип

GHSA-84fq-6626-w5fg

больше 8 лет назад

CORS Token Disclosure in crumb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2014-7193

The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which allows remote attackers to obtain sensitive information, and potentially obtain the ability to spoof requests to non-CORS routes, via a crafted web site that is visited by an application consumer.

CVSS2: 5.8
0%
Низкий
около 11 лет назад
github логотип
GHSA-84fq-6626-w5fg

CORS Token Disclosure in crumb

0%
Низкий
больше 8 лет назад

Уязвимостей на страницу