A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can bypass intended security controls and potentially expose sensitive information.
History

Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can bypass intended security controls and potentially expose sensitive information.
Title CORS Vulnerability in feast-dev/feast
Weaknesses CWE-346
References
Metrics cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-03-20T10:10:54.541Z

Updated: 2025-03-20T18:15:18.661Z

Reserved: 2024-11-21T18:16:46.029Z

Link: CVE-2024-11602

cve-icon Vulnrichment

Updated: 2025-03-20T17:47:51.165Z

cve-icon NVD

Status : Received

Published: 2025-03-20T10:15:25.337

Modified: 2025-03-20T10:15:25.337

Link: CVE-2024-11602

cve-icon Redhat

No data.