CVE-2021-39185 | http4s up to 0.21.26/0.22.2/0.23.1/1.0.0-M24 CORS Configuration cross-domain policy (EUVD-2021-1978)
A vulnerability has been found in http4s up to 0.21.26/0.22.2/0.23.1/1.0.0-M24 and classified as critical. Affected by this issue is some unknown functionality of the component CORS Configuration. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is traded as CVE-2021-39185. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.