CVE Vulnerabilities

CVE-2012-2671

Published: Jun 17, 2012 | Modified: Aug 28, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache.

Affected Software

Name Vendor Start Version End Version
Rack-cach Rtomayko 0.3.0 (including) 0.3.0 (including)
Rack-cach Rtomayko 0.4 (including) 0.4 (including)
Rack-cach Rtomayko 0.5 (including) 0.5 (including)
Rack-cach Rtomayko 0.5.2 (including) 0.5.2 (including)
Rack-cach Rtomayko 0.5.3 (including) 0.5.3 (including)
Rack-cach Rtomayko 1.0 (including) 1.0 (including)
Rack-cach Rtomayko 1.0.1 (including) 1.0.1 (including)
Rack-cach Rtomayko 1.0.2 (including) 1.0.2 (including)
Rack-cach Rtomayko 1.0.3 (including) 1.0.3 (including)
Rack-cach Rtomayko 1.1 (including) 1.1 (including)
Ruby-rack-cache Ubuntu upstream *

References