[SECURITY] Fix Auth Bypass & CORS Misconfiguration (V-008, V-009) #63
Reference in New Issue
Block a user
Delete Branch "security/fix-auth-bypass"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
API Server security hardening:
V-009 (CVSS 8.1): Fail-secure default for auth
V-008 (CVSS 8.2): Reject CORS wildcard
Refs: SECURITY_AUDIT_REPORT.md