CVE-2026-68517
MEDIUM
6,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
Description
AI Translation Available
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.
942
Permissive Cross-domain Security Policy with Untrusted Domains
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Access Control
Potential Impacts:
Execute Unauthorized Code Or Commands
Bypass Protection Mechanism
Read Application Data
Varies By Context
Applicable Platforms
Technologies:
Web Based, Web Server
https://github.com/nicolargo/glances/security/advisories/GHSA-fp27-88fp-2phg
https://github.com/nicolargo/glances/commit/890858944ab9d03730ec6b1ba42d4015e6d…
https://github.com/nicolargo/glances/releases/tag/v4.5.6
https://github.com/nicolargo/glances/security/advisories/GHSA-fp27-88fp-2phg