Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2013-02-08T20:00:00
Updated: 2024-08-06T14:18:09.586Z
Reserved: 2012-12-06T00:00:00
Link: CVE-2013-0263
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-02-08T20:55:01.640
Modified: 2024-11-21T01:47:11.133
Link: CVE-2013-0263
Redhat