Количество 2
Количество 2
CVE-2020-10591
An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potentially unsafe dependency on Origin headers, and are not configurable. This allows remote attackers to discover host information, nodes, API metadata, and references to usernames via api/v1/apikey.
GHSA-6566-9526-52v6
Exposure of Sensitive Information to an Unauthorized Actor in Concord
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-10591 An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potentially unsafe dependency on Origin headers, and are not configurable. This allows remote attackers to discover host information, nodes, API metadata, and references to usernames via api/v1/apikey. | CVSS3: 7.5 | 1% Низкий | почти 6 лет назад | |
GHSA-6566-9526-52v6 Exposure of Sensitive Information to an Unauthorized Actor in Concord | CVSS3: 7.5 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу