rack-cors Project rack-cors 1.0.3 for Ruby

CPE Details

rack-cors Project rack-cors 1.0.3 for Ruby
1.0.3
2019-11-18
18h21 +00:00
2019-11-18
18h21 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:rack-cors_project:rack-cors:1.0.3:*:*:*:*:ruby:*:*

Informations

Vendor

rack-cors_project

Product

rack-cors

Version

1.0.3

Target Software

ruby

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-18978 2019-11-14 19h21 +00:00 An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
5.3
Medium