VDB
Sign up
MEDIUM

GHSA-xc85-32mf-xpv8

Rack arbitrary code execution via timing attack

Quick fix

GHSA-xc85-32mf-xpv8 — rack: upgrade to the fixed version with the command below.

bundle update rack

Details

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rack
Introduced in: 1.5.0Fixed in: 1.5.2
Fixbundle update rack
RubyGems/rack
Introduced in: 1.4.0Fixed in: 1.4.5
Fixbundle update rack
RubyGems/rack
Introduced in: 1.3.0Fixed in: 1.3.10
Fixbundle update rack
RubyGems/rack
Introduced in: 1.2.0Fixed in: 1.2.8
Fixbundle update rack
RubyGems/rack
Introduced in: 1.1.0Fixed in: 1.1.6
Fixbundle update rack

References