Hi,
im struggeling to understand how exactly this could be exploited.
Our instances in question have some CORS rules as the only security measures on the (HTTPS) reverse proxy level.
What risks come with this vulnerability, could an attacker hijack a user session?
What else could an attacker do?
Cheers
Jens