Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.
{ "nvd_published_at": "2022-12-27T22:15:00Z", "github_reviewed_at": "2022-12-30T19:18:39Z", "severity": "CRITICAL", "github_reviewed": true, "cwe_ids": [ "CWE-346" ] }