Skip to content

Server has no auth and is open to any origin with overly permissive CORS #28

@broady

Description

@broady

The server is exposed unauthenticated and serves requests with overly board CORS headers, allowing a malicious website to control farfield without a password.

More detail:
https://ampcode.com/threads/T-019d93c9-c0cd-754b-8671-4b171ce99a07

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions