Overly permissive cross-domain whitelist in Adobe Flash Player - CVE-2019-8075
Published: September 27, 2019 / Updated: November 17, 2020
Adobe Flash Player
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass the CORS protection mechanism.
The vulnerability exists due to incorrect processing of the "Origin" HTTP header that is supplied within HTTP request in Adobe Flash player. A remote attacker can bypass implemented same origin policy restrictions and gain access to sensitive information from another domain.