PT-2021-19959 · Mockserve · Mockserve

Published

2021-08-16

·

Updated

2022-07-02

·

CVE-2021-32827

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MockServer (affected versions not specified)
Description The issue concerns MockServer, open source software used for mocking systems via HTTP or HTTPS. An attacker can trick a victim into visiting a malicious site while running MockServer locally, allowing the attacker to run arbitrary code on the MockServer machine. This is possible due to an overly broad default CORS configuration, which allows any site to send cross-site requests. Additionally, MockServer's use of Javascript or Velocity templates for dynamic expectations may allow an attacker to execute arbitrary code on behalf of MockServer. By combining these issues, an attacker could serve a malicious page to compromise a developer running MockServer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32827
GHSA-V3CG-H3F6-2242

Affected Products

Mockserve