CVE-2019-14860 describes a Cross-Origin Resource Sharing (CORS) misconfiguration in Red Hat Fuse and Red Hat Syndesis, allowing all origins. This vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low complexity, requiring user interaction, to achieve high confidentiality impact. While no active exploits, public exploit code, or significant community discussion have been observed, the misconfiguration could enable phishing attacks and unauthorized information access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.5.0CPE matchmatch criteria | cpe:2.3:a:redhat:fuse:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:syndesis:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.