CVE Vulnerabilities

CVE-2017-20146

Origin Validation Error

Published: Dec 27, 2022 | Modified: Jan 06, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
Ubuntu
MEDIUM

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Handlers Gorillatoolkit * 1.3.0 (excluding)
Golang-github-coreos-discovery-etcd-io Ubuntu kinetic *
Golang-github-coreos-discovery-etcd-io Ubuntu lunar *
Golang-github-coreos-discovery-etcd-io Ubuntu mantic *
Golang-github-coreos-discovery-etcd-io Ubuntu trusty *
Golang-github-coreos-discovery-etcd-io Ubuntu xenial *
Golang-github-gorilla-handlers Ubuntu bionic *
Golang-github-gorilla-handlers Ubuntu kinetic *
Golang-github-gorilla-handlers Ubuntu lunar *
Golang-github-gorilla-handlers Ubuntu mantic *
Golang-github-gorilla-handlers Ubuntu trusty *
Golang-github-gorilla-handlers Ubuntu xenial *

References