{"id":"GHSA-927h-x4qj-r242","summary":"github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error","details":"The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.","aliases":["CVE-2018-20744","GO-2023-1792"],"modified":"2024-05-20T21:53:21Z","published":"2022-05-14T01:33:06Z","database_specific":{"github_reviewed_at":"2023-06-14T14:53:20Z","nvd_published_at":"2019-01-28T08:29:00Z","cwe_ids":["CWE-346"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-20744"},{"type":"WEB","url":"https://github.com/gofiber/fiber/issues/2338"},{"type":"WEB","url":"https://github.com/rs/cors/issues/55"},{"type":"WEB","url":"https://github.com/gofiber/fiber/pull/2339"},{"type":"WEB","url":"https://github.com/rs/cors/pull/57"},{"type":"PACKAGE","url":"https://github.com/gofiber/fiber"},{"type":"WEB","url":"https://web.archive.org/web/20200227091122/http://www.securityfocus.com/bid/106834"},{"type":"WEB","url":"https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-chen.pdf"}],"affected":[{"package":{"name":"github.com/gofiber/fiber/v2","ecosystem":"Go","purl":"pkg:golang/github.com/gofiber/fiber/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.43.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-927h-x4qj-r242/GHSA-927h-x4qj-r242.json"}},{"package":{"name":"github.com/rs/cors","ecosystem":"Go","purl":"pkg:golang/github.com/rs/cors"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-927h-x4qj-r242/GHSA-927h-x4qj-r242.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}