github.com/gorilla/handlers
Activity
- Latest release
- 2y ago
- Total releases
- 8
- Cadence
- ~9 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- May 23, 2017
| Version | Released | |
|---|---|---|
v1.5.2
patch
|
v1.5.2
patch
Dependencies (1)
|
|
v1.5.1
patch
|
v1.5.1
patch
Dependencies (1)
|
|
v1.5.0
minor
|
v1.5.0
minor
Dependencies (1)
|
|
v1.4.2
patch
|
v1.4.2
patch
|
|
v1.4.1
patch
|
v1.4.1
patch
|
|
v1.4.0
minor
|
v1.4.0
minor
|
|
v1.3.0
minor
|
v1.3.0
minor
|
|
v1.2.1
initial
1 CVE
CVE-2017-20146
GHSA-jcr6-mmjj-pchw
GO-2020-0020
Dec 28, 2022
gorilla/handlers may allow requester to bypass expected behavior of the Same Origin Policy
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy. Fixed in
1.3.0
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.2.1
initial
|