Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Go Cors Project Subscribe
Filtered by product Go Cors
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20744 1 Go Cors Project 1 Go Cors 2019-02-20 4.3 MEDIUM 5.9 MEDIUM
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.