CVE-2018-20744
ADVISORY - githubSummary
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
EPSS Score: 0.00146 (0.354)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Origin Validation Error
ADVISORY - github
Origin Validation Error
NIST
CREATED
UPDATED
ADVISORY IDCVE-2018-20744
EXPLOITABILITY SCORE
2.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.9mediumGitHub
CREATED
UPDATED
ADVISORY IDGHSA-927h-x4qj-r242
EXPLOITABILITY SCORE
2.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.9mediumGoLang
CREATED
UPDATED
ADVISORY IDGO-2023-1792
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-