VYPR

RubyGems package

activerecord-session_store

pkg:gem/activerecord-session_store

Vulnerabilities (1)

  • CVE-2019-25025Mar 5, 2021
    affected < 2.0.0fixed 2.0.0

    The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when delivering information about whether a guessed session ID is valid. Consequently, remote attackers can leverage timing discrepanci