VDB

CVE-2019-25211

CVE-2019-25211 PUBLISHED CVSS 9.100000381469727 CRITICAL

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.

EPSS 0.43% · 35.0th percentile

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.43%
35.0th percentile

Affected Products

VendorProductVersions
Salesforcecommunity
Ubuntu:22.04:LTSgolang-github-gin-contrib-cors0, 1.3.1-1
Ubuntu:24.04:LTSgolang-github-gin-contrib-cors0, 1.4.0-1
Ubuntu:25.10golang-github-gin-contrib-cors1.4.0-1, 0
Ubuntu:20.04:LTSgolang-github-gin-contrib-cors0, 1.3.0-2

Timeline

  • Jun 28, 2024 CVE Published
  • Jun 29, 2024 EPSS Score
  • Jul 22, 2024 EPSS Score
  • Aug 14, 2024 EPSS Score
  • Sep 6, 2024 EPSS Score
  • Sep 29, 2024 EPSS Score
  • Oct 22, 2024 EPSS Score
  • Nov 14, 2024 EPSS Score
  • Dec 8, 2024 EPSS Score
  • Dec 30, 2024 EPSS Score
  • Jan 22, 2025 EPSS Score
  • Feb 14, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›