VDB

RHSA-2023%3A0814

RHSA-2023%3A0814 PUBLISHED CVSS 9.100000381469727 CRITICAL

A flaw was found in CORS Filter feature from the go-restful package. When a user inputs a domain which is in AllowedDomains, all domains starting with the same pattern are accepted. This issue could allow an attacker to break the CORS policy by allowing any page to make requests and retrieve data on behalf of users.

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Red Hatcryostat-tech-preview/cryostat-reports-rhel8@sha256:3ae672568790ef1d2e0870d4c016186b37365144082920510dbd2426b336a896_amd64 as a component of Cryostat 2 on RHEL 8cryostat-tech-preview/cryostat-reports-rhel8@sha256:3ae672568790ef1d2e0870d4c016186b37365144082920510dbd2426b336a896_amd64
Red Hatcryostat-tech-preview/cryostat-rhel8-operator@sha256:20ab3fc7104fe007eb9d5d0df368b86ed6d01a9cb0c2b4595bcf9b677e7a22f8_amd64 as a component of Cryostat 2 on RHEL 8*
Red Hatcryostat-tech-preview/cryostat-rhel8@sha256:3bec4e0d5e0e7f0a86374661222e68590f14181f230444a8a042904e772db9db_amd64 as a component of Cryostat 2 on RHEL 8cryostat-tech-preview/cryostat-rhel8@sha256:3bec4e0d5e0e7f0a86374661222e68590f14181f230444a8a042904e772db9db_amd64
Red Hatcryostat-tech-preview/jfr-datasource-rhel8@sha256:2718b97731f10e50c53a1e86e00d3fbb80a99b7fa0151858a6e355c501e1b392_amd64 as a component of Cryostat 2 on RHEL 8cryostat-tech-preview/jfr-datasource-rhel8@sha256:2718b97731f10e50c53a1e86e00d3fbb80a99b7fa0151858a6e355c501e1b392_amd64
Red Hatcryostat-tech-preview/cryostat-operator-bundle@sha256:704d50bc5a2ba7910344e6ec6d30bbabccd560628ac82b89d66f53a2ddf1140e_amd64 as a component of Cryostat 2 on RHEL 8cryostat-tech-preview/cryostat-operator-bundle@sha256:704d50bc5a2ba7910344e6ec6d30bbabccd560628ac82b89d66f53a2ddf1140e_amd64
Red Hatcryostat-tech-preview/cryostat-grafana-dashboard-rhel8@sha256:475397e4ba392d1bf197280f078b2aa024ee562ab0b4772b15b9fd773f52e716_amd64 as a component of Cryostat 2 on RHEL 8cryostat-tech-preview/cryostat-grafana-dashboard-rhel8@sha256:475397e4ba392d1bf197280f078b2aa024ee562ab0b4772b15b9fd773f52e716_amd64

Timeline

  • Feb 20, 2023 CVE Published
  • Mar 18, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›