parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.
History

Fri, 25 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Gin-contrib
Gin-contrib cors
CPEs cpe:2.3:a:gin-contrib:cors:*:*:*:*:*:*:*:*
Vendors & Products Gin-contrib
Gin-contrib cors
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat rhmt
CPEs cpe:/a:redhat:rhmt:1.8::el8
Vendors & Products Redhat
Redhat rhmt

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-06-28T00:00:00

Updated: 2024-10-25T18:02:26.343Z

Reserved: 2024-06-28T00:00:00

Link: CVE-2019-25211

cve-icon Vulnrichment

Updated: 2024-08-05T03:00:19.391Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-29T00:15:02.107

Modified: 2024-08-01T13:41:57.540

Link: CVE-2019-25211

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-07-02T00:00:00Z

Links: CVE-2019-25211 - Bugzilla