ontohub-backend icon indicating copy to clipboard operation
ontohub-backend copied to clipboard

[Security] Bump rack-cors from 1.0.2 to 1.1.1

Open dependabot-preview[bot] opened this issue 5 years ago • 1 comments

Bumps rack-cors from 1.0.2 to 1.1.1. This update includes security fixes.

Vulnerabilities fixed

Sourced from The Ruby Advisory Database.

rack-cors directory traversal via path An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

Patched versions: >= 1.0.4 Unaffected versions: none

Sourced from The GitHub Security Advisory Database.

High severity vulnerability that affects rack-cors An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

Affected versions: < 1.0.4

Changelog

Sourced from rack-cors's changelog.

1.1.1 - 2019-12-29

Changed

  • Allow //* to match // and / paths

1.1.0 - 2019-11-19

Changed

  • Use Rack::Utils.escape_path instead of Rack::Utils.escape
  • Require Rack 2.0 for escape_path method
  • Don't try to clean path if invalid.
  • Return 400 (Bad Request) on preflights with invalid path

1.0.6 - 2019-11-14

Changed

  • Use Rack::Utils.escape to make compat with Rack 1.6.0

1.0.5 - 2019-11-14

Changed

  • Update Gem spec to require rack >= 1.6.0

1.0.4 - 2019-11-13

Security

  • Escape and resolve path before evaluating resource rules (thanks to Colby Morgan)

1.0.3 - 2019-03-24

Changed

  • Don't send 'Content-Type' header with pre-flight requests
  • Allow ruby array for vary header config
Commits
  • 6fbc109 Up gem version
  • 8572837 Allow more flexible <resource>/* matching
  • a5b2d5a Bump puma from 3.12.1 to 3.12.2 in /examples/rails5
  • f962395 Bump rack from 2.0.6 to 2.0.8 in /examples/rack
  • 14b6bed Bump rack from 2.0.7 to 2.0.8 in /examples/rails5
  • dc58f04 Remove Rails 4 example
  • f42315e Update Rails/Rack examples
  • c8f9a61 Return 400 on preflight for invalid requests
  • ed91aef Don’t attempt to clean path if it is invalid
  • f971f24 Check to see if path is valid before cleaning
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

dependabot-preview[bot] avatar Jan 06 '20 05:01 dependabot-preview[bot]

Codecov Report

Merging #579 into master will not change coverage. The diff coverage is n/a.

Impacted file tree graph

@@          Coverage Diff           @@
##           master    #579   +/-   ##
======================================
  Coverage     100%    100%           
======================================
  Files         399     399           
  Lines       10675   10675           
======================================
  Hits        10675   10675

Continue to review full report at Codecov.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update adfe0b6...2453059. Read the comment docs.

codecov-io avatar Jan 06 '20 05:01 codecov-io