VDB
Sign up
HIGH7.5

GHSA-j6w9-fv6q-3q52

Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names

Quick fix

GHSA-j6w9-fv6q-3q52 — rack: upgrade to the fixed version with the command below.

bundle update rack

Details

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it possible for an attacker to forge a secure or host-only cookie prefix.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rack
Introduced in: 0Fixed in: 2.1.4
Fixbundle update rack
RubyGems/rack
Introduced in: 2.2.0Fixed in: 2.2.3
Fixbundle update rack

References