Back to search
CVE-2017-11173
Published: Jul 13, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain name, then example.com.example.net (as well as example.com-example.net) would be inadvertently allowed.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://seclists.org/fulldisclosure/2017/Jul/22
x_refsource_MISC
DSA-3931
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now