We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-8183

CORS Misconfiguration in prefecthq/prefect



Description

A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to the database, resulting in potential data leaks, loss of confidentiality, service disruption, and data integrity risks.

Reserved 2024-08-26 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


HIGH: 7.6CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Problem types

CWE-346 Origin Validation Error

Product status

Any version before 3.0.3
affected

References

huntr.com/bounties/b801de43-ff9f-4db9-b583-4797d4f7d3d2

github.com/...ommit/a69266e077169b8a32ad76b1dd3ea63b96d011c2

cve.org (CVE-2024-8183)

nvd.nist.gov (CVE-2024-8183)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-8183

Support options

Helpdesk Chat, Email, Knowledgebase