Lucene search

K
cvelistMitreCVELIST:CVE-2018-20745
HistoryJan 28, 2019 - 8:00 a.m.

CVE-2018-20745

2019-01-2808:00:00
mitre
www.cve.org
2
yii
cors
security
misconfiguration

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

35.4%

Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

35.4%

Related for CVELIST:CVE-2018-20745