Candidate: CVE-2017-11173 PublicDate: 2017-07-13 03:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11173 http://seclists.org/fulldisclosure/2017/Jul/22 https://github.com/cyu/rack-cors/commit/42ebe6caa8e85ffa9c8a171bda668ba1acc7a5e6 https://packetstormsecurity.com/files/143345/rack-cors-Missing-Anchor.html Description: Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain name, then example.com.example.net (as well as example.com-example.net) would be inadvertently allowed. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_ruby-rack-cors: upstream: https://github.com/cyu/rack-cors/commit/42ebe6caa8e85ffa9c8a171bda668ba1acc7a5e6 upstream_ruby-rack-cors: released (0.4.1-1) precise/esm_ruby-rack-cors: DNE trusty_ruby-rack-cors: ignored (reached end-of-life) trusty/esm_ruby-rack-cors: DNE (trusty was needs-triage) vivid/ubuntu-core_ruby-rack-cors: DNE xenial_ruby-rack-cors: released (0.4.0-1+deb9u1build0.16.04.1) yakkety_ruby-rack-cors: ignored (reached end-of-life) zesty_ruby-rack-cors: released (0.4.0-1+deb9u1build0.17.04.1) artful_ruby-rack-cors: not-affected (0.4.1-1) bionic_ruby-rack-cors: not-affected (0.4.1-1) cosmic_ruby-rack-cors: not-affected (0.4.1-1) disco_ruby-rack-cors: not-affected (0.4.1-1) devel_ruby-rack-cors: not-affected (0.4.1-1)