Skip to content

GHSA Sync: 1 brand new advisory#754

Merged
postmodern merged 5 commits intorubysec:masterfrom
jasnow:ghsa-syncbot-2024-02-27-07_31_13
Feb 27, 2024
Merged

GHSA Sync: 1 brand new advisory#754
postmodern merged 5 commits intorubysec:masterfrom
jasnow:ghsa-syncbot-2024-02-27-07_31_13

Conversation

@jasnow
Copy link
Contributor

@jasnow jasnow commented Feb 27, 2024

GHSA Sync: 1 brand new advisory: gems/rack-cors/CVE-2024-27456.yml

@postmodern postmodern merged commit 4c738a9 into rubysec:master Feb 27, 2024
@kirkath
Copy link

kirkath commented Feb 27, 2024

@jasnow @postmodern I am getting alerted on this for rack-cors 1.0.6, don't think that was intended

Screenshot 2024-02-27 at 4 26 40 PM

seems like it was introduced in 2.0.1 as per cyu/rack-cors#274 . are we missing

unaffected_versions:
  - "< 2.0.0"

or something?

@aprescott
Copy link

#755 adds affected version metadata

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants