Lucene search

K
redhatcveRedhat.comRH:CVE-2019-16782
HistoryApr 08, 2020 - 9:49 p.m.

CVE-2019-16782

2020-04-0821:49:55
redhat.com
access.redhat.com
9

0.002 Low

EPSS

Percentile

65.0%

A flaw was found in rubygem-rack in versions prior to 1.6.12 and 2.0.8. An information leak may allow an attacker to find and hijack sessions using timing attacks targeting the session ID. The highest threat from the vulnerability is to data confidentiality.

Mitigation

There is no mitigation for this issue, the flaw can only be resolved by applying updates.