This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format. . Package : ruby-rack-corsVersion : 0.2.9-1+deb8u1 CVE ID : CVE-2019-18978 This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format. For Debian 8 "Jessie", this problem has been fixed in version 0.2.9-1+deb8u1. We recommend that you upgrade your ruby-rack-cors packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance ruby-rack-cors module to address directory traversal vulnerability on Debian 8, safeguarding sensitive assets.. ruby-rack-cors, Debian LTS, security update, directory traversal, package upgrade. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.