Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22214
HistoryDec 20, 2019 - 4:00 a.m.

Cross-Origin Resource Sharing (CORS)

2019-12-2004:00:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.001

Percentile

48.2%

assembly-wsmaster-war uses an insecure cross-origin resource sharing (CORS) policy. The CORS configuration is enabled by default, which would allow a malicious web site to start an arbitrary Che workspace on behalf of the authenticated user in a manner of a CSRF attack.

EPSS

0.001

Percentile

48.2%