Skip to main content

Origin Validation Error

CVE-2018-20744

Severity Medium
Score 5.9/10

Summary

The Olivier Poitrey Go CORS handler in versions prior to 1.5.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design and could lead to CORS misconfiguration security problems. This vulnerability also affects the package github.com/gofiber/fiber/v2 versions 2.0.x prior to 2.43.0, and github.com/go-chi/cors versions prior to 1.1.0.

  • HIGH
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-346 - Origin Validation Error

The software does not properly verify that the source of data or communication is valid.

Advisory Timeline

  • Published