Possible Information Leak / Session Hijack Vulnerability in Rack
Vulnerability Description
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-16782
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/rack/rack/security/advisories/GHSA-hrqr-hxpp-chr3
- https://github.com/rack/rack/commit/7fecaee81f59926b6e1913511c90650e76673b38
- http://www.openwall.com/lists/oss-security/2019/12/18/3
- http://www.openwall.com/lists/oss-security/2019/12/18/2
- http://www.openwall.com/lists/oss-security/2019/12/19/3
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZXMWILCICQLA2BYSP6I2CRMUG53YBLX/
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html
- http://www.openwall.com/lists/oss-security/2020/04/08/1
- http://www.openwall.com/lists/oss-security/2020/04/09/2
More from rack
View All →Affected Vendor
rack
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.