Intel

AIKIDO-2024-10409

uppy is vulnerable to Overly Permissive Cross-domain Whitelist

Overly Permissive Cross-domain Whitelist Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 4, 2024

30

Low Risk

This Affects:

jsuppy
3.5.0 - 4.5.0
Fixed in 4.6.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to overly permissive cross-domain whitelisting. When the corsOrigins environment variable is set to *, it allows requests from any origin, bypassing intended security restrictions and exposing the application to potential Cross-site Request Forgery (CSRF) or data theft attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

uppy is vulnerable to Overly Permissive Cross-domain Whitelist in versions 3.5.0 - 4.5.0.

How to fix this

Upgrade the uppy library to the patch version.