CVE-2017-11173
ruby-rack-cors - security update
8.8
HIGH
CVSS 3.1
EPSS 2.3%
Description
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain name, then example.com.example.net (as well as example.com-example.net) would be inadvertently allowed.
How to fix CVE-2017-11173
To remediate CVE-2017-11173, upgrade the affected package to a fixed version below.
- —upgrade to 0.4.1-1 or later
- —upgrade to 0.4.0-1+deb9u1 or later
- —upgrade to 0.4.1 or later
Is CVE-2017-11173 being exploited?
Low — EPSS is 2.3%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 0.4.1-1
- from 0, < 0.4.0-1+deb9u1
- from 0, < 0.4.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |