VDB
Sign up
—

GO-2024-2574

Insecure CORS Configuration allowing wildcard origin with credentials in github.com/gofiber/fiber/v2

Quick fix

GO-2024-2574 — github.com/gofiber/fiber/v2: upgrade to the fixed version with the command below.

go get github.com/gofiber/fiber/v2@v2.52.1

Details

The CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard ("*") while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/gofiber/fiber/v2
Introduced in: 0Fixed in: 2.52.1
Fixgo get github.com/gofiber/fiber/v2@v2.52.1

References