CVE-2018-20744
MEDIUMGO Cors < 1.3.0 - Origin Validation Error
Title source: ruleDescription
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
Scores
CVSS v3
5.9
EPSS
0.0015
EPSS Percentile
34.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-346
Status
published
Affected Products (3)
go_cors_project/go_cors
< 1.3.0
gofiber/fiber
< 2.43.0Go
rs/cors
< 1.5.0Go
Timeline
Published
Jan 28, 2019
Tracked Since
Feb 18, 2026