VYPR

Rack Protection

by Sinatrarb

Source repositories

CVEs (1)

  • CVE-2018-1000119MedMar 7, 2018
    risk 0.32cvss 5.9epss 0.02

    Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This…