GHSL-2024-036: GHSL-2024-035_GHSL-2024-036: CORS misconfguration and Reflected XSS in Casdoor - CVE-2024-41657, CVE-2024-41658
Published Aug 14, 2024
·Updated
Casdoor is vulnerable to a CORS misconfiguration and a reflected Cross-Site Scripting (XSS) vulnerability, both of which may allow an attacker to take actions on behalf of the signed-in user.
Affected Software
1 affected component
Casdoor Casdoor
Event History
Aug 14, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of GHSL-2024-036?
GHSL-2024-036 has a risk rating of 50, indicating a moderate severity level.
2
How do I fix GHSL-2024-036?
To fix GHSL-2024-036, update Casdoor to version 1.577.0 or later, which addresses both the CORS misconfiguration and XSS vulnerabilities.
3
What specific vulnerabilities are involved in GHSL-2024-036?
GHSL-2024-036 involves a CORS misconfiguration and reflected XSS vulnerabilities identified as CVE-2024-41657 and CVE-2024-41658.
4
What impact does GHSL-2024-036 have on users?
GHSL-2024-036 can allow an attacker to perform actions on behalf of a signed-in user, potentially compromising user data and accounts.
5
Which software is affected by GHSL-2024-036?
GHSL-2024-036 affects the Casdoor software platform.