CVE-2012-2671

EUVD-2022-4211
The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
rtomaykorack-cach
0.3.0
rtomaykorack-cach
0.4
rtomaykorack-cach
0.5
rtomaykorack-cach
0.5.2
rtomaykorack-cach
0.5.3
rtomaykorack-cach
1.0
rtomaykorack-cach
1.0.1
rtomaykorack-cach
1.0.2
rtomaykorack-cach
1.0.3
rtomaykorack-cach
1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ruby-rack-cache
bookworm
1.2-4.1
fixed
bullseye
1.2-4.1
fixed
sid
1.2-4.1
fixed
trixie
1.2-4.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby-rack-cache
hardy
dne
lucid
dne
natty
dne
oneiric
dne
precise
dne