Origin Validation Error
CVE-2018-20744
Summary
The Olivier Poitrey Go CORS handler in versions prior to 1.5.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design and could lead to CORS misconfiguration security problems. This vulnerability also affects the package github.com/gofiber/fiber/v2 versions 2.0.x prior to 2.43.0, and github.com/go-chi/cors versions prior to 1.1.0.
- HIGH
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- NONE
- NONE
CWE-346 - Origin Validation Error
The software does not properly verify that the source of data or communication is valid.
Advisory Timeline
- Published