CVE-2018-20745

MEDIUM5.9EPSS 0.12%

Yii Incorrectly Implements CORS

Published: 5/14/2022Modified: 2/16/2024
Also known as:GHSA-cr6r-6xm9-ww22

Description

Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

References (4)