Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-2671

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2012-2671
Last Modified 28 Aug 2013 02:47:11
Published 16 Jun 2012 11:41:41
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-2671

Summary

The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache.

Vulnerable Systems

Application

  • Rtomayko Rack-cach 0.3.0

  • Rtomayko Rack-cach 0.4

  • Rtomayko Rack-cach 0.5

  • Rtomayko Rack-cach 0.5.2

  • Rtomayko Rack-cach 0.5.3

  • Rtomayko Rack-cach 1.0

  • Rtomayko Rack-cach 1.0.1

  • Rtomayko Rack-cach 1.0.2

  • Rtomayko Rack-cach 1.0.3

  • Rtomayko Rack-cach 1.1


References

CONFIRM - https://github.com/rtomayko/rack-cache/pull/52

CONFIRM - https://github.com/rtomayko/rack-cache/commit/2e3a64d07daac4c757cc57620f2288e865a09b90

CONFIRM - https://github.com/rtomayko/rack-cache/blob/master/CHANGES

MISC - https://bugzilla.redhat.com/show_bug.cgi?id=824520

MISC - https://bugzilla.novell.com/show_bug.cgi?id=763650

MLIST - [oss-security] 20120606 Re: CVE request: rack-cache caches sensitive headers (Set-Cookie)

MLIST - [oss-security] 20120606 CVE request: rack-cache caches sensitive headers (Set-Cookie)

FEDORA - FEDORA-2012-8439


Last Updated: 27 May 2016 10:56:32