VYPR

Go Cors

by Go Cors Project

CVEs (1)

  • CVE-2018-20744MedJan 28, 2019
    risk 0.00cvss 5.9epss 0.01

    The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.