github / github/codeql

Codeql to detect CORS misconfiguration in go webapp

Offen
#9,303 6 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Go
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

Here is how a sample go code vulnerable to CORS misconfiguration looks like

```
import(
"github.com/go-chi/cors"
)

var corsOpts = cors.Options{
AllowedOrigins: []string{"*"},
AllowCredentials: true
}
```

It does not validate the origin header and allows authenticated cross-origin requests. I was testing codeql on a popular GitHub repo and unfortunately, it was not able to detect it using lgtm.com website. So I thought this query can be added to codeql for detecting this kind of bugs.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.