PT-2019-10199 · Yii · Yii

Chenjj

·

Publicado

2019-01-28

·

Atualizado

2022-05-14

·

CVE-2018-20745

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Yii versions 2.x through 2.0.15.1
Description: The issue arises from the active conversion of a wildcard CORS policy into reflecting an arbitrary Origin header value. This behavior is incompatible with the CORS security design and could lead to CORS misconfiguration security problems.
Recommendations: For versions 2.x through 2.0.15.1, consider disabling the automatic conversion of wildcard CORS policies to prevent reflecting arbitrary Origin header values until a patch is available. Restrict access to sensitive resources to minimize the risk of exploitation.

Correção

Origin Validation Error

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-20745
GHSA-CR6R-6XM9-WW22

Produtos afetados

Yii