diff --git a/bundle-audit-time.txt b/bundle-audit-time.txt index b9c0390..54671d4 100644 --- a/bundle-audit-time.txt +++ b/bundle-audit-time.txt @@ -1 +1 @@ -2024-02-28T09:36:40+01:00 +2024-02-28T09:45:20+01:00 diff --git a/bundle-audit.json b/bundle-audit.json index dc5585f..7a050f7 100644 --- a/bundle-audit.json +++ b/bundle-audit.json @@ -1 +1 @@ -{"version":"0.9.1","created_at":"2024-02-28 09:36:39 +0100","results":[{"type":"unpatched_gem","gem":{"name":"rack-cors","version":"2.0.1"},"advisory":{"path":"/home/wiseadvice/.local/share/ruby-advisory-db/gems/rack-cors/CVE-2024-27456.yml","id":"CVE-2024-27456","url":"https://github.com/advisories/GHSA-785g-282q-pwvx","title":"Rack CORS Middleware has Insecure File Permissions","date":"2024-02-26","description":"rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions\nfor the .rb files.\n","cvss_v2":null,"cvss_v3":null,"cve":"2024-27456","osvdb":null,"ghsa":"785g-282q-pwvx","unaffected_versions":["< 2.0.1"],"patched_versions":[],"criticality":null}}]} \ No newline at end of file +{"version":"0.9.1","created_at":"2024-02-28 09:45:20 +0100","results":[]} \ No newline at end of file diff --git a/report.txt b/report.txt index ce17423..8900c02 100644 --- a/report.txt +++ b/report.txt @@ -1,10 +1 @@ -Name: rack-cors -Version: 2.0.1 -CVE: CVE-2024-27456 -GHSA: GHSA-785g-282q-pwvx -Criticality: Unknown -URL: https://github.com/advisories/GHSA-785g-282q-pwvx -Title: Rack CORS Middleware has Insecure File Permissions -Solution: remove or disable this gem until a patch is available! - -Vulnerabilities found! +No vulnerabilities found