CVE Vulnerabilities

CVE-2017-20146

Origin Validation Error

Published: Dec 27, 2022 | Modified: Apr 11, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
HandlersGorillatoolkit*1.3.0 (excluding)
Golang-github-coreos-discovery-etcd-ioUbuntukinetic*
Golang-github-coreos-discovery-etcd-ioUbuntulunar*
Golang-github-coreos-discovery-etcd-ioUbuntumantic*
Golang-github-coreos-discovery-etcd-ioUbuntutrusty*
Golang-github-coreos-discovery-etcd-ioUbuntuxenial*
Golang-github-gorilla-handlersUbuntubionic*
Golang-github-gorilla-handlersUbuntuesm-apps/bionic*
Golang-github-gorilla-handlersUbuntuesm-apps/xenial*
Golang-github-gorilla-handlersUbuntukinetic*
Golang-github-gorilla-handlersUbuntulunar*
Golang-github-gorilla-handlersUbuntumantic*
Golang-github-gorilla-handlersUbuntutrusty*
Golang-github-gorilla-handlersUbuntuxenial*

References