parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Migration Toolkit for Containers 1.8 | RedHat | rhmtc/openshift-migration-controller-rhel8:v1.8.4-22 | * |
Golang-github-gin-contrib-cors | Ubuntu | mantic | * |