rpm package
opensuse/rubygem-rack&distro=openSUSE Leap 15.1
pkg:rpm/opensuse/rubygem-rack&distro=openSUSE%20Leap%2015.1
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-16782 | — | < 2.0.8-lp151.3.3.1 | 2.0.8-lp151.3.3.1 | Dec 18, 2019 | There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually store | ||
| CVE-2018-16471 | — | < 2.0.8-lp151.3.3.1 | 2.0.8-lp151.3.3.1 | Nov 13, 2018 | There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value coul |
- CVE-2019-16782Dec 18, 2019affected < 2.0.8-lp151.3.3.1fixed 2.0.8-lp151.3.3.1
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually store
- CVE-2018-16471Nov 13, 2018affected < 2.0.8-lp151.3.3.1fixed 2.0.8-lp151.3.3.1
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value coul