CVE-2018-20745

Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:*

Information

Published : 2019-01-28 00:29

Updated : 2019-02-20 08:26


NVD link : CVE-2018-20745

Mitre link : CVE-2018-20745


JSON object : View

CWE
CWE-346

Origin Validation Error

Advertisement

dedicated server usa

Products Affected

yiiframework

  • yii