CVE-2019-14860

MEDIUM

Redhat Fuse < 7.5.0 - Permissive CORS Policy

Title source: rule
STIX 2.1

Description

It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.

Scores

CVSS v3 6.5
EPSS 0.0028
EPSS Percentile 51.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-942
Status published
Products (2)
redhat/fuse < 7.5.0
redhat/syndesis
Published Nov 08, 2019
Tracked Since Feb 18, 2026