A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can bypass intended security controls and potentially expose sensitive information.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can bypass intended security controls and potentially expose sensitive information. | |
| Title | CORS Vulnerability in feast-dev/feast | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:10:54.541Z
Updated: 2025-03-20T18:15:18.661Z
Reserved: 2024-11-21T18:16:46.029Z
Link: CVE-2024-11602
Updated: 2025-03-20T17:47:51.165Z
Status : Received
Published: 2025-03-20T10:15:25.337
Modified: 2025-03-20T10:15:25.337
Link: CVE-2024-11602
No data.