Headline
GHSA-jcr6-mmjj-pchw: gorilla/handlers may allow requester to bypass expected behavior of the Same Origin Policy
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.
gorilla/handlers may allow requester to bypass expected behavior of the Same Origin Policy
Moderate severity GitHub Reviewed Published Dec 28, 2022 • Updated Dec 30, 2022
Related news
CVE-2017-20146: [bugfix] Don't return the origin header when configured to * (#116) · gorilla/handlers@9066371
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.