Lucene search

K
osvGoogleOSV:CVE-2018-20745
HistoryJan 28, 2019 - 8:29 a.m.

CVE-2018-20745

2019-01-2808:29:00
Google
osv.dev
8

AI Score

7

Confidence

High

EPSS

0.001

Percentile

35.4%

Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.

AI Score

7

Confidence

High

EPSS

0.001

Percentile

35.4%

Related for OSV:CVE-2018-20745