CVE-2024-27456
Rack CORS Middleware has Insecure File Permissions
EPSS 0.77%
Description
rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
How to fix CVE-2024-27456
To remediate CVE-2024-27456, upgrade the affected package to a fixed version below.
- RubyGems/rack-cors—upgrade to 2.0.2 or later
Is CVE-2024-27456 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 2.0.1, < 2.0.2