Apache Helix REST
cpe:2.3:a:apache:helix:*:*:*:*:*:*:*
- <= 2.0.0
A Cross-Origin Resource Sharing (CORS) vulnerability has been identified in the Apache Helix REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in all platforms through version 2.0.0. This vulnerability allows remote attackers, controlling a web page visited by an authorized user, to read responses from and send cross-origin requests to administrative REST endpoints. The issue arises because the CORS filter indiscriminately allows requests from any origin, permits credentials, and reflects arbitrary method and header values in preflight responses.
Exploitation of this vulnerability could lead to unauthorized access to administrative REST endpoints, allowing attackers to read responses or issue requests that could affect the application's state or data.
Users are advised to upgrade to Apache Helix version 2.0.1, which addresses this CORS vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.