Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
NA
CVE-2024-27456
Published: 26/02/2024 Updated: 26/02/2024
Vulnerability Summary
rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
Vendor Advisories
Debian CVElist Bug Report Logs: ruby-rack-cors: CVE-2024-27456
Debian Bug report logs - #1064862 ruby-rack-cors: CVE-2024-27456 Package: src:ruby-rack-cors; Maintainer for src:ruby-rack-cors is Debian Ruby Team <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 26 Feb 2024 19:45:04 UTC Severity: important Tags: ...
References
https://github.com/cyu/rack-cors/issues/274
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1064862
https://nvd.nist.gov
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started