Description

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.

INFO

Published Date :

2024-06-28T00:00:00.000Z

Last Modified :

2025-11-03T18:07:54.695Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2019-25211 vulnerability.

Vendors Products
Gin-contrib
  • Cors
Redhat
  • Rhmt

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact