-
Notifications
You must be signed in to change notification settings - Fork 284
Closed
Labels
All For OneSubmissions to the All for One, One for All bountySubmissions to the All for One, One for All bounty
Description
Query PR
Language
Javascript
CVE(s) ID list
-GHSA-2p3c-p3qw-69r4 (CVE WIP)
CWE
CWE-942
Report
The query covers Overly Permissive CORS vulnerability, occurs when the server CORS configuration is too permissive , potentially leading to CSRF attacks. Consequently, an attacker might force authenticated users to submit a request to a Web application against which they are currently authenticated.
I used a dataflow configuration looking for RemoteFlowSource, true and null flowing to the CORS configuration.
The library covered is apollo server. I plan to include 1/2 more.
Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc).
- Yes
- No
Blog post link
No response
Metadata
Metadata
Assignees
Labels
All For OneSubmissions to the All for One, One for All bountySubmissions to the All for One, One for All bounty