CVE-2017-20146
27.12.2022, 22:15
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gorillatoolkit | handlers | 𝑥 < 1.3.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| golang-github-coreos-discovery-etcd-io |
| ||||||||||||||||||
| golang-github-gorilla-handlers |
|
Common Weakness Enumeration
References