216.73.216.6

CVE-2024-41657

· Published 20/08/2024 21:15 · Modified 28/08/2024 16:13

Labels: CVE-2024-41657 2024-08-20CVE-2024-41657CWE-697CWE-942[email protected]

Essential information

Published
20/08/2024 21:15
Modified
28/08/2024 16:13
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor as the logged in user. Due to the a logic error in checking only for a prefix when authenticating the Origin header, any domain can create a valid subdomain with a valid subdomain prefix (Ex: localhost.example.com), allowing the website to make requests to Casdoor as the current signed-in user.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
casbin / casdoor cpe:2.3:a:casbin:casdoor:*:*:*:*:*:*:*:*

References