PT-2021-8576 · Github.Com/Gorilla/Handlers+13 · Github.Com/Gorilla/Handlers+3

·

CVE-2017-20146

·

Published

2021-04-14

·

Updated

2025-04-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue concerns the usage of the CORS handler, which may apply improper CORS headers. This allows the requester to explicitly control the value of the Access-Control-Allow-Origin header, bypassing the expected behavior of the Same Origin Policy. No information is provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20146
GHSA-JCR6-MMJJ-PCHW
GO-2020-0020

Affected Products

Github.Com/Gorilla/Handlers
Golang-Github-Coreos-Discovery-Etcd-Io
Golang-Github-Gorilla-Handlers
Handlers