Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-16779

Опубликовано: 16 дек. 2019
Источник: nvd
CVSS3: 5.8
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:excon_project:excon:*:*:*:*:*:*:*:*
Версия до 0.71.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 61%
0.00414
Низкий

5.8 Medium

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-664
CWE-362

Связанные уязвимости

CVSS3: 5.8
ubuntu
около 6 лет назад

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.

CVSS3: 5.8
debian
около 6 лет назад

In RubyGem excon before 0.71.0, there was a race condition around pers ...

suse-cvrf
около 6 лет назад

Security update for rubygem-excon

suse-cvrf
больше 5 лет назад

Security update for rubygem-excon

CVSS3: 5.8
github
около 6 лет назад

In RubyGem excon, interrupted Persistent Connections May Leak Response Data

EPSS

Процентиль: 61%
0.00414
Низкий

5.8 Medium

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-664
CWE-362