CVE-2024-8024

A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a restrictive CORS policy is crucial to prevent such security issues.
References
Link Resource
https://huntr.com/bounties/bda53fab-88aa-4e03-8d9d-4cf50a98ffc7 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:youdao:qanything:1.4.1:*:*:*:*:*:*:*

History

01 Aug 2025, 01:45

Type Values Removed Values Added
CPE cpe:2.3:a:youdao:qanything:1.4.1:*:*:*:*:*:*:*
References () https://huntr.com/bounties/bda53fab-88aa-4e03-8d9d-4cf50a98ffc7 - () https://huntr.com/bounties/bda53fab-88aa-4e03-8d9d-4cf50a98ffc7 - Exploit, Third Party Advisory
Summary
  • (es) Existe una vulnerabilidad de configuración incorrecta de CORS en la versión 1.4.1 de netease-youdao/qanything. Esta vulnerabilidad permite a un atacante eludir la política de mismo origen, lo que podría provocar la exposición de información confidencial. Implementar correctamente una política de CORS restrictiva es crucial para prevenir estos problemas de seguridad.
First Time Youdao qanything
Youdao

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-08-01 01:45


NVD link : CVE-2024-8024

Mitre link : CVE-2024-8024

CVE.ORG link : CVE-2024-8024


JSON object : View

Products Affected

youdao

  • qanything
CWE
CWE-346

Origin Validation Error