Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-jcr6-mmjj-pchw: gorilla/handlers may allow requester to bypass expected behavior of the Same Origin Policy

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

ghsa
#git

gorilla/handlers may allow requester to bypass expected behavior of the Same Origin Policy

Moderate severity GitHub Reviewed Published Dec 28, 2022 • Updated Dec 30, 2022

Related news

CVE-2017-20146: [bugfix] Don't return the origin header when configured to * (#116) · gorilla/handlers@9066371

Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.