Lucene search

K
osvGoogleOSV:GHSA-XC85-32MF-XPV8
HistoryMay 05, 2022 - 2:48 a.m.

Rack arbitrary code execution via timing attack

2022-05-0502:48:42
Google
osv.dev
23

0.084 Low

EPSS

Percentile

94.4%

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

Rows per page:
1-10 of 321