Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21431
HistorySep 05, 2019 - 3:55 a.m.

Cross-site Websocket Hijacking (CSWSH)

2019-09-0503:55:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.001

Percentile

40.0%

github.com/rancher/rancher is vulnerable to cross-site websocket hijacking (CSWSH). It does not check the Origin header in the clients handshake request for trusted origin, allowing an attacker to send an authenticated request to Rancher Server using a Rancher with the privilege of a victim.

EPSS

0.001

Percentile

40.0%

Related for VERACODE:21431