PT-2017-11796 · Ruby · Rack-Cors

Jens Mueller

·

Publicado

2017-07-13

·

Atualizado

2020-03-03

·

CVE-2017-11173

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rack-cors versions prior to 0.4.1
Description The issue allows a malicious third-party site to perform CORS requests due to a missing anchor in the generated regex. This could lead to unintended domains being allowed if the configuration is set to trust specific domain names. For instance, if the configuration is intended to allow only the trusted example.com domain name and not the malicious example.net domain name, then example.com.example.net (as well as example.com-example.net) would be inadvertently allowed.
Recommendations For versions prior to 0.4.1, update to version 0.4.1 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2017-11173
DSA-3931-1
GHSA-2J9C-9VMV-7M39

Produtos afetados

Rack-Cors