Junglewise Threat Intelligence

CVE-2017-11173: Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request

CVE-2017-11173 · Severity: low · CVSS 3.1 · Published 2018-07-31

Technologies: rack-cors (RubyGems). Vendors: RubyGems.

Executive brief

Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request

Affected products

  • RubyGems rack-cors

Related threats