HIGH8.8
GHSA-2j9c-9vmv-7m39
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
Quick fix
GHSA-2j9c-9vmv-7m39 — rack-cors: upgrade to the fixed version with the command below.
bundle update rack-corsDetails
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted `example.com` domain name and not the malicious `example.net` domain name, then `example.com.example.net` (as well as `example.com-example.net`) would be inadvertently allowed.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-11173[ADVISORY]
- https://github.com/cyu/rack-cors/commit/42ebe6caa8e85ffa9c8a171bda668ba1acc7a5e6[WEB]
- https://github.com/cyu/rack-cors[PACKAGE]
- https://packetstormsecurity.com/files/143345/rack-cors-Missing-Anchor.html[WEB]
- http://seclists.org/fulldisclosure/2017/Jul/22[WEB]
- http://www.debian.org/security/2017/dsa-3931[WEB]