Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
NA
CVE-2024-27456
Published: 26/02/2024 Updated: 26/02/2024
Vulnerability Summary
rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
Vendor Advisories
Debian CVElist Bug Report Logs: ruby-rack-cors: CVE-2024-27456
Debian Bug report logs - #1064862 ruby-rack-cors: CVE-2024-27456 Package: src:ruby-rack-cors; Maintainer for src:ruby-rack-cors is Debian Ruby Team <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 26 Feb 2024 19:45:04 UTC Severity: important Tags: ...
References
https://github.com/cyu/rack-cors/issues/274
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1064862
https://nvd.nist.gov
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started