CVE-2024-23823
vantage6's CORS settings overly permissive
4.2
MEDIUM
CVSS 3.1
EPSS 0.31%
描述
### Impact The vantage6 server has no restrictions on CORS settings. It should be possible for people to set the allowed origins of the server. The impact is limited because v6 does not use session cookies ### Patches No ### Workarounds No
如何修補 CVE-2024-23823
要修補 CVE-2024-23823,請將受影響套件升級到下列已修補版本。
- PyPI/vantage6—升級至 4.3.0 或更新版本
- —升級至 4.3.0 或更新版本
- —升級至 4.2.1 或更新版本
CVE-2024-23823 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 4.3.0
- from 0, < 4.3.0
- from 0, < 4.2.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.2 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |