REDHAT-BUG-824520: Medium severity Ruby Rack::Cache vulnerability
Published May 23, 2012
·Updated
The Rack::Cache rubygem has a flaw where it will cache sensitive headers (such as Set-Cookie response headers), which could leak potentially sensitive information.
This has been corrected in upstream git [1].
[1] https://github.com/rtomayko/rack-cache/commit/2e3a64d07daac4c757cc57620f2288e865a09b90
Affected Software
1 affected component
Ruby Rack::Cache
Event History
May 23, 2012
Data Sourced
04:27 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-824520?
The severity of REDHAT-BUG-824520 is classified as high due to the potential leakage of sensitive information.
2
How do I fix REDHAT-BUG-824520?
To fix REDHAT-BUG-824520, upgrade to the corrected version of the Rack::Cache gem from upstream.
3
What type of data does REDHAT-BUG-824520 affect?
REDHAT-BUG-824520 affects sensitive headers, such as Set-Cookie response headers.
4
Which software is impacted by REDHAT-BUG-824520?
REDHAT-BUG-824520 impacts the Ruby Rack::Cache rubygem.
5
Is there a workaround for REDHAT-BUG-824520?
There is no known workaround for REDHAT-BUG-824520; updating the gem is recommended.