CORS Bypass Vulnerability in StackStorm Web UI
CVE-2019-9580
6.1MEDIUM
Key Information:
- Vendor
Stackstorm
- Status
- Vendor
- CVE Published:
- 9 March 2019
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2019-9580?
In the StackStorm Web UI, a vulnerability exists that allows for the circumvention of the Cross-Origin Resource Sharing (CORS) protection mechanism when a 'null' origin value is used. This flaw can potentially lead to cross-site scripting (XSS) attacks, posing a significant risk for applications relying on CORS for security. It affects StackStorm Web UI versions prior to 2.9.3 and those in the 2.10.x line prior to 2.10.3. It is advisable for users to upgrade to the latest versions to mitigate this risk.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
