socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.
Stay updated with the latest patches and releases. Plan your sofware desisgn. Avoid common known vulnerabilities fixed by the open source community
Latest patch release: 0.13.1
Latest minor release: 0.17.1
Latest major release: 1.7.0-rc.2
Maintain your licence declarations and avoid unwanted licences to protect your IP the way you intended.
MIT - MIT License