MEDIUM5.3
GHSA-pf8f-w267-mq2h
The rack-cors rubygem may allow directory traveral
Quick fix
GHSA-pf8f-w267-mq2h — rack-cors: upgrade to the fixed version with the command below.
bundle update rack-corsDetails
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-18978[ADVISORY]
- https://github.com/cyu/rack-cors/commit/e4d4fc362a4315808927011cbe5afcfe5486f17d[WEB]
- https://github.com/cyu/rack-cors[PACKAGE]
- https://github.com/cyu/rack-cors/compare/v1.0.3...v1.0.4[WEB]
- https://lists.debian.org/debian-lts-announce/2020/02/msg00004.html[WEB]
- https://lists.debian.org/debian-lts-announce/2020/10/msg00000.html[WEB]
- https://usn.ubuntu.com/4571-1[WEB]
- https://www.debian.org/security/2021/dsa-4918[WEB]