Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13278
HistoryJan 29, 2019 - 1:59 a.m.

Cross-origin Resource Sharing (CORS) Bypass

2019-01-2901:59:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.001

Percentile

35.4%

yiisoft/yii2 is vulnerable to cross-origin resource sharing (CORS) bypass. It is possible because Yii2 CORS filter exposes origin header value when the policy is configured to wildcard origins.

EPSS

0.001

Percentile

35.4%

Related for VERACODE:13278