Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29589
HistoryMar 08, 2021 - 2:45 a.m.

Information Disclosure

2021-03-0802:45:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.002 Low

EPSS

Percentile

65.0%

activerecord-session_store is vulnerable to information disclosure. The package does not use a constant-time approach when validating a session ID. Remote attackers are able to analyze the response time to discover session ID. This vulnerability is related issue to CVE-2019-16782.