Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An Origin Validation Error in the elysia-cors library thru 1.3.0 allows attackers to bypass Cross-Origin Resource Sharing (CORS) restrictions. The library incorrectly validates the supplied origin by checking if it is a substring of any domain in the site's CORS policy, rather than performing an exact match. For example, a malicious origin like "notexample.com", "example.common.net" is whitelisted when the site's CORS policy specifies "example.com." This vulnerability enables unauthorized access to user data on sites using the elysia-cors library for CORS validation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
elysiajs-cors 安全漏洞
Vulnerability Description
elysiajs-cors是elysia开源的一个插件。 elysiajs-cors 1.3.0及之前版本存在安全漏洞,该漏洞源于源验证错误,可能导致绕过跨资源共享限制。
CVSS Information
N/A
Vulnerability Type
N/A