CVE-2018-20745: Medium severity yii framework vulnerability
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-20745?
CVE-2018-20745 is a vulnerability in Yii 2.x through 2.0.15.1 that converts a wildcard CORS policy into reflecting an arbitrary Origin header value.
What is the severity of CVE-2018-20745?
The severity of CVE-2018-20745 is medium with a severity value of 5.9.
How does CVE-2018-20745 affect Yii?
CVE-2018-20745 affects Yii 2.x through 2.0.15.1 by introducing CORS misconfiguration security problems.
How can I fix CVE-2018-20745?
To fix CVE-2018-20745, upgrade to Yii version 2.0.16 or later.
Where can I find more information about CVE-2018-20745?
You can find more information about CVE-2018-20745 at the following references: - [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-20745) - [GitHub Issue](https://github.com/yiisoft/yii2/issues/16193) - [Conference Paper](https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-chen.pdf)