First published: Tue Oct 15 2019(Updated: )
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Fuse | <7.5.0 | |
Redhat Syndesis |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-14860.
The severity of CVE-2019-14860 is high with a severity value of 7.
CVE-2019-14860 allows an attacker to conduct phishing attacks and access unauthorized information.
The affected software for CVE-2019-14860 is Syndesis.
To fix CVE-2019-14860, the Syndesis configuration for Cross-Origin Resource Sharing needs to be restricted to specific trusted origins.