github / github/codeql

Codeql to detect CORS misconfiguration in go webapp

Open
#9,303 6 comments 0 reactions 0 assignees View on GitHub
Go
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

Here is how a sample go code vulnerable to CORS misconfiguration looks like

```
import(
"github.com/go-chi/cors"
)

var corsOpts = cors.Options{
AllowedOrigins: []string{"*"},
AllowCredentials: true
}
```

It does not validate the origin header and allows authenticated cross-origin requests. I was testing codeql on a popular GitHub repo and unfortunately, it was not able to detect it using lgtm.com website. So I thought this query can be added to codeql for detecting this kind of bugs.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.