Skip to content

[JS]: Overly Permissive CORS Query #793

Description

@maikypedia

Query PR

github/codeql#14342

Language

Javascript

CVE(s) ID list

-GHSA-2p3c-p3qw-69r4 (CVE WIP)

CWE

CWE-942

Report

The query covers Overly Permissive CORS vulnerability, occurs when the server CORS configuration is too permissive , potentially leading to CSRF attacks. Consequently, an attacker might force authenticated users to submit a request to a Web application against which they are currently authenticated.

I used a dataflow configuration looking for RemoteFlowSource, true and null flowing to the CORS configuration.

The library covered is apollo server. I plan to include 1/2 more.

Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc).

  • Yes
  • No

Blog post link

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

All For OneSubmissions to the All for One, One for All bounty

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions