Description
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-14527 | Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled. |
References
History
No history.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2024-09-16T21:04:10.396Z
Reserved: 2021-02-26T00:00:00.000Z
Link: CVE-2021-27786
No data.
Status : Modified
Published: 2022-06-09T17:15:08.560
Modified: 2024-11-21T05:58:33.907
Link: CVE-2021-27786
No data.
OpenCVE Enrichment
No data.
EUVD