REDHAT-BUG-909072: Medium severity rack vulnerability
James Tucker (raggi) reports:
CVE: CVE-2013-0262 Software: Rack (rack.github.com) Type of vulnerability: Information Disclosure Vulnerable code: https://github.com/rack/rack/blob/master/lib/rack/file.rb#L56 Patch: https://github.com/rack/rack/commit/6f237e4c9fab649d3750482514f0fde76c56ab30 Versions affected: All versions after 1.4.0 Versions fixed: 1.4.5, 1.5.2 Reporter: Ben Murphy
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-909072?
The severity of REDHAT-BUG-909072 is classified as an information disclosure vulnerability.
How do I fix REDHAT-BUG-909072?
To fix REDHAT-BUG-909072, update your Rack installation to a version that addresses the vulnerability, specifically to version 1.5.0 or higher.
What software is affected by REDHAT-BUG-909072?
REDHAT-BUG-909072 affects Rack versions earlier than 1.5.0.
What type of vulnerability is REDHAT-BUG-909072?
REDHAT-BUG-909072 is categorized as an information disclosure vulnerability.
Who reported REDHAT-BUG-909072?
REDHAT-BUG-909072 was reported by James Tucker, also known as raggi.