Beveiligingsadvies

CVE-2018-20745

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-01-28 08:00:00
Laatst bijgewerkt 2024-09-17 00:56:20
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.