PT-2020-14854 · Winston · Winston

Published

2020-10-28

·

Updated

2020-11-03

·

CVE-2020-16263

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Winston version 1.5.4
Description The issue concerns a CORS configuration that trusts arbitrary origins, allowing requests to be made and viewed by arbitrary origins.
Recommendations For version 1.5.4, update the CORS configuration to only trust specific origins to prevent arbitrary requests.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-16263

Affected Products

Winston