SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data gateway service in the application. This gateway service includes an API which is not properly configured to reject requests from unexpected sources.
References
Configurations
No configuration.
History
12 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-12 16:15
Updated : 2025-05-12 17:32
NVD link : CVE-2025-46737
Mitre link : CVE-2025-46737
CVE.ORG link : CVE-2025-46737
JSON object : View
Products Affected
No product.
CWE
CWE-346
Origin Validation Error