An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random origins by accepting the arbitrary Origin: example.com header and responding with 200 OK and a wildcard Access-Control-Allow-Origin: * header.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Smart_asset | Damstratechnology | 2020.7 (including) | 2020.7 (including) |