fig. 01 — GHSA-r48q-9g5r-8q2h, the advisory selected below
// advisories
GHSA-r48q-9g5r-8q2h
CRITICALCVE-2022-1996
CORS filters that use an AllowedDomains configuration parameter can match domains outside the specified set, permitting an attacker to avoid the CORS policy.