USN-4571-1: rack-cors vulnerability
Publication date
5 October 2020
Overview
rack-cors would allow unintended access to files over the network.
Releases
Packages
- ruby-rack-cors - provides support for Cross-Origin Resource Sharing (CORS) for Rack compatible web applications
Details
It was discovered that rack-cors did not properly handle relative file
paths. An attacker could use this vulnerability to access arbitrary files.
It was discovered that rack-cors did not properly handle relative file
paths. An attacker could use this vulnerability to access arbitrary files.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
16.04 xenial | ruby-rack-cors – 0.4.0-1+deb9u2build0.16.04.1 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.