VYPR

Active Record Session Store

by Rubyonrails

CVEs (1)

  • CVE-2019-25025MedMar 5, 2021
    risk 0.28cvss 5.3epss 0.02

    The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when delivering information about whether a guessed session ID is valid. Consequently, remote attackers can leverage timing…