Логотип exploitDog
bind:CVE-2020-10591
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-10591

Количество 2

Количество 2

nvd логотип

CVE-2020-10591

почти 6 лет назад

An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potentially unsafe dependency on Origin headers, and are not configurable. This allows remote attackers to discover host information, nodes, API metadata, and references to usernames via api/v1/apikey.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6566-9526-52v6

почти 4 года назад

Exposure of Sensitive Information to an Unauthorized Actor in Concord

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-10591

An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potentially unsafe dependency on Origin headers, and are not configurable. This allows remote attackers to discover host information, nodes, API metadata, and references to usernames via api/v1/apikey.

CVSS3: 7.5
1%
Низкий
почти 6 лет назад
github логотип
GHSA-6566-9526-52v6

Exposure of Sensitive Information to an Unauthorized Actor in Concord

CVSS3: 7.5
1%
Низкий
почти 4 года назад

Уязвимостей на страницу