CVE-2019-14860
published 2019-11-08CVE-2019-14860: It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.17%
63.7th percentile
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | fuse | < 7.5.0 | 7.5.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
syndesis: default CORS configuration is allow all
vendor_redhat·2019-10-29·CVSS 6.5
CVE-2019-14860 [MEDIUM] CWE-942 syndesis: default CORS configuration is allow all
syndesis: default CORS configuration is allow all
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.
GHSA
GHSA-xw65-g8p2-hc6q: It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins
ghsa_unreviewed·2022-05-24
CVE-2019-14860 [MEDIUM] GHSA-xw65-g8p2-hc6q: It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.
No detection rules found.
No public exploits indexed.
2019-11-08
Published