Modeling CORS frameworks with CodeQL to find security vulnerabilities
ID: 5b8b41bb-8e85-54c7-bbac-4e2b3e45b41f
STIX ID: report--5b8b41bb-8e85-54c7-bbac-4e2b3e45b41f
Feed Name: GitHub Security Lab
Threat Score
This GitHub Security Lab blog post describes how to use CodeQL to model Go CORS frameworks (with examples for Gin) to find CORS misconfigurations that can lead to origin reflection and credentialed cross-origin requests. It walks through modeling header writes and config structures, writing predicates and queries to detect vulnerable patterns, and discusses reducing false positives and extending detection for different frameworks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
