vantage6's CORS settings overly permissive
Moderate severity
GitHub Reviewed
Published
Mar 14, 2024
in
vantage6/vantage6
•
Updated Mar 15, 2024
Description
Published by the National Vulnerability Database
Mar 14, 2024
Published to the GitHub Advisory Database
Mar 15, 2024
Reviewed
Mar 15, 2024
Last updated
Mar 15, 2024
Impact
The vantage6 server has no restrictions on CORS settings. It should be possible for people to set the allowed origins of the server.
The impact is limited because v6 does not use session cookies
Patches
No
Workarounds
No
References