CVE-2018-20744

The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:go_cors_project:go_cors:*:*:*:*:*:*:*:*

Information

Published : 2019-01-28 00:29

Updated : 2019-02-20 10:59


NVD link : CVE-2018-20744

Mitre link : CVE-2018-20744


JSON object : View

CWE
CWE-346

Origin Validation Error

Advertisement

dedicated server usa

Products Affected

go_cors_project

  • go_cors