CVE Vulnerabilities

CVE-2013-0263

Published: Feb 08, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

Affected Software

NameVendorStart VersionEnd Version
RackRack_project1.5.0 (including)1.5.0 (including)
RackRack_project1.5.1 (including)1.5.1 (including)
Red Hat Subscription Asset Manager 1.2RedHatcandlepin-0:0.7.24-1.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-0:1.2.1.1-1h.el6_4*
Red Hat Subscription Asset Manager 1.2RedHatkatello-configure-0:1.2.3.1-4h.el6_4*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-actionpack-1:3.0.10-12.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-activemodel-0:3.0.10-3.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-delayed_job-0:2.1.4-3.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-json-0:1.7.3-2.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rack-1:1.3.0-4.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rails_warden-0:0.5.5-2.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rdoc-0:3.8-6.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatthumbslug-0:0.0.28.1-1.el6_4*
RHEL 6 Version of OpenShift EnterpriseRedHatjenkins-0:1.502-1.el6op*
RHEL 6 Version of OpenShift EnterpriseRedHatopenshift-origin-cartridge-jenkins-1.4-0:1.0.3-1.el6op*
RHEL 6 Version of OpenShift EnterpriseRedHatruby193-rubygem-rack-1:1.4.1-4.el6*
RHEL 6 Version of OpenShift EnterpriseRedHatrubygem-rack-1:1.3.0-4.el6op*
Ruby-rackUbuntudevel*
Ruby-rackUbuntuesm-apps/xenial*
Ruby-rackUbuntuesm-infra-legacy/trusty*
Ruby-rackUbuntuprecise*
Ruby-rackUbuntuquantal*
Ruby-rackUbunturaring*
Ruby-rackUbuntusaucy*
Ruby-rackUbuntutrusty*
Ruby-rackUbuntutrusty/esm*
Ruby-rackUbuntuupstream*
Ruby-rackUbuntuutopic*
Ruby-rackUbuntuvivid*
Ruby-rackUbuntuwily*
Ruby-rackUbuntuxenial*
Ruby-rackUbuntuyakkety*
Ruby-rackUbuntuzesty*

References