4.3
CVSSv2

CVE-2018-20744

Published: 28/01/2019 Updated: 20/02/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Olivier Poitrey Go CORS handler up to and including 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

go cors project go cors