Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-46336

Опубликовано: 08 мая 2025
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. This issue has been patched in version 2.1.1.

A flaw was found in Rack::Session. This vulnerability allows an attacker to maintain unauthorized access to a user's session by triggering a long-running request after the user logs out.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel8Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel9Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel8Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel9Fix deferred
Red Hat Enterprise Linux 7pcsFix deferred
Red Hat Enterprise Linux 8pcsFix deferred
Red Hat Enterprise Linux 9pcsFix deferred
Red Hat Satellite 6rubygem-rackFix deferred
Red Hat Satellite 6satellite-capsule:el8/rubygem-rackFix deferred
Red Hat Satellite 6satellite:el8/rubygem-rackFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
Дефект:
CWE-367
Дефект:
CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=2365151rack: Rack::Session Session Persistence Vulnerability

EPSS

Процентиль: 6%
0.00029
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
около 1 месяца назад

Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. This issue has been patched in version 2.1.1.

CVSS3: 4.2
nvd
около 1 месяца назад

Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. This issue has been patched in version 2.1.1.

CVSS3: 4.2
debian
около 1 месяца назад

Rack::Session is a session management implementation for Rack. In vers ...

CVSS3: 4.2
github
около 1 месяца назад

Rack session gets restored after deletion

EPSS

Процентиль: 6%
0.00029
Низкий

4.2 Medium

CVSS3