CVE-2019-9580
09.03.2019, 04:29
In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.
Vendor | Product | Version |
---|---|---|
stackstorm | stackstorm | 𝑥 < 2.9.3 |
stackstorm | stackstorm | 2.10.0 ≤ 𝑥 < 2.10.3 |
𝑥
= Vulnerable software versions
References