In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Permissive Cross-domain Policy with Untrusted Domains vulnerabilities in an interactive lesson.
Start learningUpgrade github.com/BishopFox/joro/internal/api to version 1.1.1 or higher.
Affected versions of this package are vulnerable to Permissive Cross-domain Policy with Untrusted Domains through the unauthenticated local API exposed in proxy mode, which accepts cross-origin requests due to a permissive CORS policy and lack of authentication. An attacker can achieve execution of arbitrary code as the operator's user by tricking the operator into visiting a malicious web page, which then uploads a crafted plugin and triggers a restart via the operator's browser.