Autobahn|Python Origin Header Manipulation

Discussion in 'News Aggregator' started by Packet Storm, 26 Jul 2016.

  1. Packet Storm

    Packet Storm Guest

    Autobahn|Python incorrectly checks the Origin header when the 'allowedOrigins' value is set. This can allow third parties to execute legitimate requests for WAMP WebSocket requests against an Autobahn|Python/Crossbar.io server within another browser's context. This is addressed in version 0.15.0.

    Continue reading...
     

Share This Page

Loading...