An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2096-1 | ruby-rack-cors security update |
Debian DLA |
DLA-2389-1 | ruby-rack-cors security update |
Debian DSA |
DSA-4918-1 | ruby-rack-cors security update |
EUVD |
EUVD-2019-0758 | An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. |
Github GHSA |
GHSA-pf8f-w267-mq2h | The rack-cors rubygem may allow directory traveral |
Ubuntu USN |
USN-4571-1 | rack-cors vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:02:39.801Z
Reserved: 2019-11-14T00:00:00
Link: CVE-2019-18978
No data.
Status : Modified
Published: 2019-11-14T21:15:12.170
Modified: 2024-11-21T04:33:55.463
Link: CVE-2019-18978
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN