Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xc85-32mf-xpv8

Опубликовано: 05 мая 2022
Источник: github
Github: Прошло ревью

Описание

Rack arbitrary code execution via timing attack

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

Пакеты

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 1.5.0, < 1.5.2

1.5.2

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 1.4.0, < 1.4.5

1.4.5

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 1.3.0, < 1.3.10

1.3.10

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 1.2.0, < 1.2.8

1.2.8

Наименование

rack

rubygems
Затронутые версииВерсия исправления

>= 1.1.0, < 1.1.6

1.1.6

EPSS

Процентиль: 90%
0.05283
Низкий

Связанные уязвимости

ubuntu
почти 13 лет назад

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

redhat
почти 13 лет назад

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

nvd
почти 13 лет назад

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

debian
почти 13 лет назад

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, ...

EPSS

Процентиль: 90%
0.05283
Низкий