Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-4247-1 ruby-rack-protection security update
EUVD EUVD EUVD-2018-0170 Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0.
Github GHSA Github GHSA GHSA-688c-3x49-6rqj rack-protection gem timing attack vulnerability when validating CSRF token
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T12:33:49.338Z

Reserved: 2018-03-07T00:00:00

Link: CVE-2018-1000119

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-07T14:29:00.390

Modified: 2024-11-21T03:39:41.283

Link: CVE-2018-1000119

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-05-25T00:00:00Z

Links: CVE-2018-1000119 - Bugzilla

cve-icon OpenCVE Enrichment

No data.