{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-19T02:58:08.140","vulnerabilities":[{"cve":{"id":"CVE-2024-8024","sourceIdentifier":"security@huntr.dev","published":"2025-03-20T10:15:39.380","lastModified":"2026-06-17T08:21:42.570","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a restrictive CORS policy is crucial to prevent such security issues."},{"lang":"es","value":"Existe una vulnerabilidad de configuración incorrecta de CORS en la versión 1.4.1 de netease-youdao/qanything. Esta vulnerabilidad permite a un atacante eludir la política de mismo origen, lo que podría provocar la exposición de información confidencial. Implementar correctamente una política de CORS restrictiva es crucial para prevenir estos problemas de seguridad."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"netease-youdao","product":"netease-youdao/qanything","versions":[{"version":"unspecified","lessThanOrEqual":"latest","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-20T17:52:19.140799Z","id":"CVE-2024-8024","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:youdao:qanything:1.4.1:*:*:*:*:*:*:*","matchCriteriaId":"F04CF5E5-0321-47D1-BA61-739861138B7B"}]}]}],"references":[{"url":"https://huntr.com/bounties/bda53fab-88aa-4e03-8d9d-4cf50a98ffc7","source":"security@huntr.dev","tags":["Exploit","Third Party Advisory"]}]}}]}