—
GO-2024-2574
Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2
Quick fix
GO-2024-2574 — github.com/gofiber/fiber/v2: upgrade to the fixed version with the command below.
go get github.com/gofiber/fiber/v2@v2.52.1Details
The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/gofiber/fiber/v2
Introduced in:
0Fixed in: 2.52.1Fix
go get github.com/gofiber/fiber/v2@v2.52.1References
- https://github.com/gofiber/fiber/security/advisories/GHSA-fmg4-x8pw-hjhg[ADVISORY]
- https://github.com/gofiber/fiber/commit/f0cd3b44b086544a37886232d0530601f2406c23[FIX]
- http://blog.portswigger.net/2016/10/exploiting-cors-misconfigurations-for.html[WEB]
- https://codeql.github.com/codeql-query-help/javascript/js-cors-misconfiguration-for-credentials[WEB]
- https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS/Errors/CORSNotSupportingCredentials[WEB]
- https://fetch.spec.whatwg.org/#cors-protocol-and-credentials[WEB]
- https://github.com/gofiber/fiber/releases/tag/v2.52.1[WEB]
- https://saturncloud.io/blog/cors-cannot-use-wildcard-in-accesscontrolalloworigin-when-credentials-flag-is-true[WEB]