PT-2014-7828 · Hapi · Crumb

Publicado

2014-12-25

·

Atualizado

2021-07-19

·

CVE-2014-7193

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Crumb plugin versions prior to 3.0.0
Description The issue allows remote attackers to obtain sensitive information and potentially spoof requests to non-CORS routes by exploiting improper token access restriction in situations where a hapi route handler has CORS enabled. This can be achieved via a crafted web site visited by an application consumer, enabling an attacker to set a crumb token for a different domain and make requests to non-CORS routes as that user. The scenario in which this occurs is considered unlikely, as most configurations set CORS globally or not at all.
Recommendations Update to version 3.0.0 or greater.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-7193
GHSA-84FQ-6626-W5FG

Produtos afetados

Crumb