GHSA-84fq-6626-w5fg

    Dashboard / Vulnerabilities / GHSA-84fq-6626-w5fg

    GHSA-84fq-6626-w5fg

    Published: 24 Oct 2017Last Modified: 8 Nov 2023
    Aliases:

    Summary: CORS Token Disclosure in crumb

    Details: When CORS is enabled on a hapi route handler, it is possible to set a crumb token for a different domain. An attacker would need to have an application consumer visit a site they control, request a route supporting CORS, and then retrieve the token. With this token, they could possibly make requests to non CORS routes as this user. A configuration and scenario where this would occur is unlikely, as most configurations will set CORS globally (where crumb is not used), or not at all. ## Recommendation Update to version 3.0.0 or greater.

    Affected packages

    Package

    Name: crumb

    Purl: pkg:npm/crumb

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.0.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-84fq-6626-w5fg | CVE-DB