SEL-5037 Grid Configurator contains an overly permissive...
High severity
Unreviewed
Published
May 12, 2025
to the GitHub Advisory Database
•
Updated May 12, 2025
Description
Published by the National Vulnerability Database
May 12, 2025
Published to the GitHub Advisory Database
May 12, 2025
Last updated
May 12, 2025
SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data gateway service in the application. This gateway service includes an API which is not properly configured to reject requests from unexpected sources.
References