Origin Validation Error Affecting @koa/cors package, versions <5.0.0


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-KOACORS-6117545
  • published12 Dec 2023
  • disclosed11 Dec 2023
  • creditPawelJ-PL

Introduced: 11 Dec 2023

CVE-2023-49803  (opens in a new tab)
CWE-346  (opens in a new tab)

How to fix?

Upgrade @koa/cors to version 5.0.0 or higher.

Overview

@koa/cors is a Cross-Origin Resource Sharing(CORS) for koa

Affected versions of this package are vulnerable to Origin Validation Error. An attacker can bypass the Same Origin Policy (SOP) by sending a request from an untrusted origin. This is only exploitable if the middleware is used in a production environment without proper origin restrictions.

References

CVSS Scores

version 3.1