CVE-2012-2671
The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.36% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- rtomayko/rack-cach
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081812.html
- http://www.openwall.com/lists/oss-security/2012/06/06/4
- http://www.openwall.com/lists/oss-security/2012/06/06/8
- https://bugzilla.novell.com/show_bug.cgi?id=763650
- https://bugzilla.redhat.com/show_bug.cgi?id=824520
- https://github.com/rtomayko/rack-cache/blob/master/CHANGES
- https://github.com/rtomayko/rack-cache/commit/2e3a64d07daac4c757cc57620f2288e865a09b90
- https://github.com/rtomayko/rack-cache/pull/52
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081812.html
- http://www.openwall.com/lists/oss-security/2012/06/06/4
- http://www.openwall.com/lists/oss-security/2012/06/06/8
- https://bugzilla.novell.com/show_bug.cgi?id=763650
- https://bugzilla.redhat.com/show_bug.cgi?id=824520
- https://github.com/rtomayko/rack-cache/blob/master/CHANGES
- https://github.com/rtomayko/rack-cache/commit/2e3a64d07daac4c757cc57620f2288e865a09b90
- https://github.com/rtomayko/rack-cache/pull/52
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.