Security Advisory

CVE-2018-6651

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-02-05 22:00:00
Last updated 2024-08-05 06:10:10
Assigner mitre
State PUBLISHED

Description

In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victims computer.