{"id":"GHSA-2j9c-9vmv-7m39","summary":"Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request","details":"Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted `example.com` domain name and not the malicious `example.net` domain name, then `example.com.example.net` (as well as `example.com-example.net`) would be inadvertently allowed.","aliases":["CVE-2017-11173"],"modified":"2024-12-03T06:02:08.526584Z","published":"2018-07-31T18:18:39Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T20:52:24Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11173"},{"type":"WEB","url":"https://github.com/cyu/rack-cors/commit/42ebe6caa8e85ffa9c8a171bda668ba1acc7a5e6"},{"type":"PACKAGE","url":"https://github.com/cyu/rack-cors"},{"type":"WEB","url":"https://packetstormsecurity.com/files/143345/rack-cors-Missing-Anchor.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2017/Jul/22"},{"type":"WEB","url":"http://www.debian.org/security/2017/dsa-3931"}],"affected":[{"package":{"name":"rack-cors","ecosystem":"RubyGems","purl":"pkg:gem/rack-cors"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.1"}]}],"versions":["0.1.0","0.1.1","0.2.0","0.2.2","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.2.9","0.3.0","0.3.1","0.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-2j9c-9vmv-7m39/GHSA-2j9c-9vmv-7m39.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}