-
Notifications
You must be signed in to change notification settings - Fork 86
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CORS Misconfiguration 취약점 제보합니다. #626
Comments
@AkiaCode |
@Junanjunan
p.s. 해결 방법으로는 하드코딩보다 |
@AkiaCode |
Version: 6.0.7
Vuln: CORS Misconfiguration
PoC
Impact
Secure Code (core/middleware)
이와 같이 테스트가 아닌 프로덕션 환경에서는 allow_origins에 호스트를 지정 필요
Video
video.mp4
ref: b9b6bb7
https://github.com/gnuboard/g6/blob/master/core/middleware.py#L81
The text was updated successfully, but these errors were encountered: