Bug 2295302 (CVE-2019-25211) - CVE-2019-25211 github.com/gin-contrib/cors: Gin mishandles a wildcard in the origin string in github.com/gin-contrib/cors
Summary: CVE-2019-25211 github.com/gin-contrib/cors: Gin mishandles a wildcard in the ...
Keywords:
Status: NEW
Alias: CVE-2019-25211
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-07-02 21:00 UTC by OSIDB Bzimport
Modified: 2024-09-26 03:47 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2024:7164 0 None None None 2024-09-26 03:47:12 UTC

Description OSIDB Bzimport 2024-07-02 21:00:51 UTC
Gin-Gonic CORS middleware mishandles a wildcard at the end of an origin string. Examples: https://example.community/* is accepted by the origin string https://example.com/* and http://localhost.example.com/* is accepted by the origin string http://localhost/* .

Comment 1 errata-xmlrpc 2024-09-26 03:47:11 UTC
This issue has been addressed in the following products:

  Red Hat Migration Toolkit for Containers 1.8

Via RHSA-2024:7164 https://access.redhat.com/errata/RHSA-2024:7164


Note You need to log in before you can comment on or make changes to this bug.