Skip to content

Commit

Permalink
GHSA Sync: 1 brand new advisory (#754)
Browse files Browse the repository at this point in the history
  • Loading branch information
jasnow authored Feb 27, 2024
1 parent fc2aa0d commit 4c738a9
Showing 1 changed file with 16 additions and 0 deletions.
16 changes: 16 additions & 0 deletions gems/rack-cors/CVE-2024-27456.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
gem: rack-cors
cve: 2024-27456
ghsa: 785g-282q-pwvx
url: https://github.com/advisories/GHSA-785g-282q-pwvx
title: Rack CORS Middleware has Insecure File Permissions
date: 2024-02-26
description: |
rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions
for the .rb files.
notes: Never patched
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2024-27456
- https://github.com/cyu/rack-cors/issues/274
- https://github.com/advisories/GHSA-785g-282q-pwvx

0 comments on commit 4c738a9

Please sign in to comment.