7.5
CVE-2012-2671
- EPSS 2.36%
- Veröffentlicht 17.06.2012 03:41:41
- Zuletzt bearbeitet 16.06.2026 23:41:50
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.36% | 0.816 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081812.html
http://www.openwall.com/lists/oss-security/2012/06/06/4
http://www.openwall.com/lists/oss-security/2012/06/06/8
https://bugzilla.novell.com/show_bug.cgi?id=763650
https://bugzilla.redhat.com/show_bug.cgi?id=824520
https://github.com/rtomayko/rack-cache/blob/master/CHANGES
https://github.com/rtomayko/rack-cache/commit/2e3a64d07daac4c757cc57620f2288e865a09b90
https://github.com/rtomayko/rack-cache/pull/52