Skip to content

[JS]: Overly Permissive CORS Query #793

@maikypedia

Description

@maikypedia

Query PR

github/codeql#14342

Language

Javascript

CVE(s) ID list

-GHSA-2p3c-p3qw-69r4 (CVE WIP)

CWE

CWE-942

Report

The query covers Overly Permissive CORS vulnerability, occurs when the server CORS configuration is too permissive , potentially leading to CSRF attacks. Consequently, an attacker might force authenticated users to submit a request to a Web application against which they are currently authenticated.

I used a dataflow configuration looking for RemoteFlowSource, true and null flowing to the CORS configuration.

The library covered is apollo server. I plan to include 1/2 more.

Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc).

  • Yes
  • No

Blog post link

No response

Metadata

Metadata

Assignees

Labels

All For OneSubmissions to the All for One, One for All bounty

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions