CVE-2017-20146
Improper access control in github.com/gorilla/handlers
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.
El uso del controlador CORS puede aplicar encabezados CORS inadecuados, lo que permite al solicitante controlar explícitamente el valor del encabezado Access-Control-Allow-Origin, lo que omite el comportamiento esperado de la política del mismo origen.
*Credits:
Evan J Johnson
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-07-29 CVE Reserved
- 2022-12-27 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-346: Origin Validation Error
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://pkg.go.dev/vuln/GO-2020-0020 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/gorilla/handlers/commit/90663712d74cb411cbef281bc1e08c19d1a76145 | 2023-01-06 | |
https://github.com/gorilla/handlers/pull/116 | 2023-01-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gorillatoolkit Search vendor "Gorillatoolkit" | Handlers Search vendor "Gorillatoolkit" for product "Handlers" | < 1.3.0 Search vendor "Gorillatoolkit" for product "Handlers" and version " < 1.3.0" | go |
Affected
|