CVE-2024-27302

CRITICAL

go-zero <1.4.4 - SSRF

Title source: llm
STIX 2.1

Description

go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - which is an array of domains allowed in CORS policy. However, the `isOriginAllowed` uses `strings.HasSuffix` to check the origin, which leads to bypass via a malicious domain. This vulnerability is capable of breaking CORS policy and thus allowing any page to make requests and/or retrieve data on behalf of other users. Version 1.4.4 fixes this issue.

Scores

CVSS v3 9.1
EPSS 0.0025
EPSS Percentile 48.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-639
Status published
Products (2)
go-zero/go-zero < 1.4.4
zeromicro/go-zero 0 - 1.4.4Go
Published Mar 06, 2024
Tracked Since Feb 18, 2026