rack-cors
Middleware that will make Rack-based apps CORS compatible. Fork the project here: https://github.com/cyu/rack-cors
Activity
- Latest release
- 1y ago
- Total releases
- 27
- Cadence
- ~4 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Jun 02, 2010
| Version | Released | |
|---|---|---|
3.0.0
major
|
3.0.0
major
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.0.2
patch
|
2.0.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.0.1
patch
1 CVE
CVE-2024-27456
GHSA-785g-282q-pwvx
Feb 26, 2024
Rack CORS Middleware has Insecure File Permissions
Medium
rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files. Affected versions
2.0.1
Fixed in
2.0.2
References
Updated Mar 04, 2024 · Source: OSV.dev |
2.0.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.0.0
major
|
2.0.0
major
Dependencies (8)
Changelog
Compare changes
|
|
2.0.0.rc1
pre
|
2.0.0.rc1
pre
Dependencies (8)
Changelog
Compare changes
|
|
1.1.1
patch
| ||
1.1.0
minor
| ||
1.0.6
patch
| ||
1.0.5
patch
| ||
1.0.3
patch
1 CVE
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.0
minor
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.3.1
patch
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.3.0
minor
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.9
patch
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.8
patch
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.7
patch
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.6
patch
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.5
patch
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.4
patch
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.2
patch
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.1.0
initial
2 CVEs
CVE-2019-18978
GHSA-pf8f-w267-mq2h
Nov 15, 2019
The rack-cors rubygem may allow directory traveral
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 6 more Show less
0.4.0
0.4.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-11173
GHSA-2j9c-9vmv-7m39
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted Affected versions
0.1.0
0.1.1
0.2.0
0.2.2
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
+ 1 more Show less
0.4.0
Fixed in
0.4.1
References
Updated Dec 03, 2024 · Source: OSV.dev |