Skip to content

CORS settings overly permissive

Low
bartvanb published GHSA-4946-85pr-fvxh Mar 14, 2024

Package

pip vantage6 (pip)

Affected versions

< 4.2.1

Patched versions

None

Description

Impact

The vantage6 server has no restrictions on CORS settings. It should be possible for people to set the allowed origins of the server.

The impact is limited because v6 does not use session cookies

Patches

No

Workarounds

No

Severity

Low

CVE ID

CVE-2024-23823

Weaknesses