{"id":"GHSA-785g-282q-pwvx","summary":"Rack CORS Middleware has Insecure File Permissions","details":"rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.","aliases":["CVE-2024-27456"],"modified":"2024-03-04T18:51:48Z","published":"2024-02-26T18:30:31Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-02-26T22:15:06Z","nvd_published_at":"2024-02-26T16:28:00Z","cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27456"},{"type":"WEB","url":"https://github.com/cyu/rack-cors/issues/274"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-785g-282q-pwvx"},{"type":"PACKAGE","url":"https://github.com/cyu/rack-cors"},{"type":"WEB","url":"https://github.com/cyu/rack-cors/blob/878063987bd1ca956282dda95697fd821bf24d2e/CHANGELOG.md#changed"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack-cors/CVE-2024-27456.yml"}],"affected":[{"package":{"name":"rack-cors","ecosystem":"RubyGems","purl":"pkg:gem/rack-cors"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.1"},{"fixed":"2.0.2"}]}],"versions":["2.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-785g-282q-pwvx/GHSA-785g-282q-pwvx.json"}}],"schema_version":"1.9.0"}