Back to search
CVE-2012-2671
Published: Jun 17, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.novell.com/show_bug.cgi?id=763650
x_refsource_MISC
https://github.com/rtomayko/rack-cache/blob/master/CHANGES
x_refsource_CONFIRM
FEDORA-2012-8439
vendor-advisory
x_refsource_FEDORA
https://github.com/rtomayko/rack-cache/pull/52
x_refsource_CONFIRM
[oss-security] 20120606 Re: CVE request: rack-cache caches sensitive headers (Set-Cookie)
mailing-list
x_refsource_MLIST
[oss-security] 20120606 CVE request: rack-cache caches sensitive headers (Set-Cookie)
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=824520
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now