CVE-2018-20745
MEDIUMYii < 2.0.15.1 - Origin Validation Error
Title source: ruleDescription
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
Scores
CVSS v3
5.9
EPSS
0.0012
EPSS Percentile
30.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-346
Status
published
Affected Products (2)
yiiframework/yii
< 2.0.15.1
yiisoft/yii2
< 2.0.16Packagist
Timeline
Published
Jan 28, 2019
Tracked Since
Feb 18, 2026