Логотип exploitDog
bind:CVE-2025-32441
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-32441

Количество 13

Количество 13

ubuntu логотип

CVE-2025-32441

6 месяцев назад

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares the session at the beginning of request, then saves is back to the store with possible changes applied by host rack application. This way the session becomes to be a subject of race conditions in general sense over concurrent rack requests. When using the `Rack::Session::Pool` middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. Version 2.2.14 contains a patch for the issue. Some other mitigations are available. Either ensure the application invalidates sessio...

CVSS3: 4.2
EPSS: Низкий
redhat логотип

CVE-2025-32441

6 месяцев назад

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares the session at the beginning of request, then saves is back to the store with possible changes applied by host rack application. This way the session becomes to be a subject of race conditions in general sense over concurrent rack requests. When using the `Rack::Session::Pool` middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. Version 2.2.14 contains a patch for the issue. Some other mitigations are available. Either ensure the application invalidates sessio...

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2025-32441

6 месяцев назад

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares the session at the beginning of request, then saves is back to the store with possible changes applied by host rack application. This way the session becomes to be a subject of race conditions in general sense over concurrent rack requests. When using the `Rack::Session::Pool` middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. Version 2.2.14 contains a patch for the issue. Some other mitigations are available. Either ensure the application invalidates sessions

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2025-32441

6 месяцев назад

Rack is a modular Ruby web server interface. Prior to version 2.2.14, ...

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-vpfw-47h7-xj4g

6 месяцев назад

Rack session gets restored after deletion

CVSS3: 4.2
EPSS: Низкий
fstec логотип

BDU:2025-07359

6 месяцев назад

Уязвимость интерфейса модуля Rack интерпретатора языка программирования Ruby, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02564-1

3 месяца назад

Security update for rmt-server

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02429-1

4 месяца назад

Security update for rmt-server

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02330-1

4 месяца назад

Security update for rmt-server

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02329-1

4 месяца назад

Security update for rmt-server

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01586-2

5 месяцев назад

Security update for rubygem-rack

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01586-1

6 месяцев назад

Security update for rubygem-rack

EPSS: Низкий
redos логотип

ROS-20250619-01

5 месяцев назад

Множественные уязвимости rubygem-rack

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-32441

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares the session at the beginning of request, then saves is back to the store with possible changes applied by host rack application. This way the session becomes to be a subject of race conditions in general sense over concurrent rack requests. When using the `Rack::Session::Pool` middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. Version 2.2.14 contains a patch for the issue. Some other mitigations are available. Either ensure the application invalidates sessio...

CVSS3: 4.2
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-32441

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares the session at the beginning of request, then saves is back to the store with possible changes applied by host rack application. This way the session becomes to be a subject of race conditions in general sense over concurrent rack requests. When using the `Rack::Session::Pool` middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. Version 2.2.14 contains a patch for the issue. Some other mitigations are available. Either ensure the application invalidates sessio...

CVSS3: 4.2
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-32441

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares the session at the beginning of request, then saves is back to the store with possible changes applied by host rack application. This way the session becomes to be a subject of race conditions in general sense over concurrent rack requests. When using the `Rack::Session::Pool` middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. Version 2.2.14 contains a patch for the issue. Some other mitigations are available. Either ensure the application invalidates sessions

CVSS3: 4.2
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-32441

Rack is a modular Ruby web server interface. Prior to version 2.2.14, ...

CVSS3: 4.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-vpfw-47h7-xj4g

Rack session gets restored after deletion

CVSS3: 4.2
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2025-07359

Уязвимость интерфейса модуля Rack интерпретатора языка программирования Ruby, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.2
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02564-1

Security update for rmt-server

3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02429-1

Security update for rmt-server

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02330-1

Security update for rmt-server

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02329-1

Security update for rmt-server

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:01586-2

Security update for rubygem-rack

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01586-1

Security update for rubygem-rack

6 месяцев назад
redos логотип
ROS-20250619-01

Множественные уязвимости rubygem-rack

CVSS3: 7.5
5 месяцев назад

Уязвимостей на страницу