CVE Published: 27/12/2022 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: Go |
Vendor: github.com/gorilla/handlers |
Product: github.com/gorilla/handlers Status : PUBLISHED
CVE-2017-20146 Description
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.