Origin Validation Error Affecting github.com/jub0bs/fcors/internal/radix package, versions <0.9.0
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMJUB0BSFCORSINTERNALRADIX-6808796
- published 5 May 2024
- disclosed 3 May 2024
- credit jub0bs
How to fix?
Upgrade github.com/jub0bs/fcors/internal/radix
to version 0.9.0 or higher.
Overview
Affected versions of this package are vulnerable to Origin Validation Error due to the implementation of CORS middleware that incorrectly processes origin patterns with shared proper suffixes. An attacker can exploit this flaw to conduct cross-origin attacks from untrusted origins by crafting requests that match the improperly allowed origin patterns.
References
CVSS Scores
version 3.1