Origin Validation Error Affecting github.com/gofiber/fiber/v2/middleware/cors package, versions <2.52.1


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.04% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMGOFIBERFIBERV2MIDDLEWARECORS-6261588
  • published22 Feb 2024
  • disclosed21 Feb 2024
  • creditJuan Calderon-Perez

Introduced: 21 Feb 2024

CVE-2024-25124  (opens in a new tab)
CWE-346  (opens in a new tab)

How to fix?

Upgrade github.com/gofiber/fiber/v2/middleware/cors to version 2.52.1 or higher.

Overview

Affected versions of this package are vulnerable to Origin Validation Error due to insecure configurations allowing the setting of Access-Control-Allow-Origin header to a wildcard * while also having this header set to true. This can lead to unauthorized access to sensitive user data and expose the system to various types of attacks.

Note: The browser fetch api, browsers and utilities that enforce CORS policies are not affected by this.

CVSS Scores

version 3.1