VDB
Sign up
HIGH8.8

GHSA-2j9c-9vmv-7m39

Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request

Quick fix

GHSA-2j9c-9vmv-7m39 — rack-cors: upgrade to the fixed version with the command below.

bundle update rack-cors

Details

Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted `example.com` domain name and not the malicious `example.net` domain name, then `example.com.example.net` (as well as `example.com-example.net`) would be inadvertently allowed.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rack-cors
Introduced in: 0Fixed in: 0.4.1
Fixbundle update rack-cors

References