GO-2022-0619
Dashboard / Vulnerabilities / GO-2022-0619
Summary: Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3
Details: CORS filters that use an AllowedDomains configuration parameter can match domains outside the specified set, permitting an attacker to avoid the CORS policy. The AllowedDomains configuration parameter is documented as a list of allowed origin domains, but values in this list are applied as regular expression matches. For example, an allowed domain of "example.com" will match the Origin header "example.com.malicious.domain".
References: https://github.com/emicklei/go-restful/commit/f292efff46ae17e9d104f865a60a39a2ae9402f1, https://github.com/emicklei/go-restful/issues/489
Affected packages
Package
Name: github.com/emicklei/go-restful
Purl: pkg:golang/github.com/emicklei/go-restful
Affected ranges
Type: SEMVER
Events:
