Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2615 | Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor as the logged in user. Due to the a logic error in checking only for a prefix when authenticating the Origin header, any domain can create a valid subdomain with a valid subdomain prefix (Ex: localhost.example.com), allowing the website to make requests to Casdoor as the current signed-in user. |
Github GHSA |
GHSA-mchx-7j67-8mcf | Casdoor CORS misconfiguration (GHSL-2024-035) |
Wed, 28 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-697 |
Tue, 20 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Casbin
Casbin casdoor |
|
| CPEs | cpe:2.3:a:casbin:casdoor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Casbin
Casbin casdoor |
|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor as the logged in user. Due to the a logic error in checking only for a prefix when authenticating the Origin header, any domain can create a valid subdomain with a valid subdomain prefix (Ex: localhost.example.com), allowing the website to make requests to Casdoor as the current signed-in user. | |
| Title | GHSL-2024-035: Casdoor CORS misconfiguration | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-20T20:54:45.045Z
Reserved: 2024-07-18T15:21:47.482Z
Link: CVE-2024-41657
Updated: 2024-08-20T20:54:06.623Z
Status : Analyzed
Published: 2024-08-20T21:15:13.687
Modified: 2024-08-28T16:13:35.140
Link: CVE-2024-41657
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA