Aqua Vulnerability Database
Get Demo
Vulnerabilities
Misconfiguration
Runtime Security
Compliance
CVE Vulnerabilities
CVE-2024-27456
Published:
Feb 26, 2024
| Modified:
Feb 26, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
NEGLIGIBLE
Additional information
NVD
https://nvd.nist.gov/vuln/detail/CVE-2024-27456
CWE
https://cwe.mitre.org/data/definitions/.html
rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
Affected Software
Name
Vendor
Start Version
End Version
Ruby-rack-cors
Ubuntu
bionic
*
Ruby-rack-cors
Ubuntu
trusty
*
Ruby-rack-cors
Ubuntu
xenial
*
References
https://github.com/cyu/rack-cors/issues/274
Aqua Container Security