GO-2024-2604

    Dashboard / Vulnerabilities / GO-2024-2604

    GO-2024-2604

    Published: 11 Mar 2024Last Modified: 20 May 2024

    Summary: CORS Filter bypass in github.com/zeromicro/go-zero

    Details: The CORS Filter feature in go-zero allows users to specify an array of domains allowed in the CORS policy. However, the isOriginAllowed function uses strings.HasSuffix to check the origin, which can lead to a bypass via a domain like "evil-victim.com". This vulnerability is capable of breaking CORS policy and thus allowing any page to make requests and retrieve data on behalf of other users.

    Affected packages

    Package

    Name: github.com/zeromicro/go-zero

    Purl: pkg:golang/github.com/zeromicro/go-zero

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.4.4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2024-2604 | CVE-DB