CVE-2020-10591 is a high-severity vulnerability affecting Walmart Labs Concord versions prior to 1.44.0. The flaw stems from an unsafe dependency of CORS Access-Control-Allow-Origin headers on Origin headers, which are not configurable. This allows unauthenticated remote attackers to discover sensitive information such as host details, nodes, API metadata, and usernames by accessing the /api/v1/apikey endpoint. While the CVSS score is 7.5 (High), indicating a significant potential for information disclosure, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.44.0CPE matchmatch criteria | cpe:2.3:a:walmart:concord:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.