PT-2019-14831 · Rack+3 · Rack+3

Will Leinweber

·

Publicado

2019-12-18

·

Atualizado

2026-03-13

·

CVE-2019-16782

CVSS v3.1

6.3

Média

VetorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rack versions prior to 1.6.12 Rack versions prior to 2.0.8
Description There's a possible information leak / session hijack issue in Rack. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison.
Recommendations For versions prior to 1.6.12, apply the 1-6-session-timing-attack.patch to fix the issue. For versions prior to 2.0.8, apply the 2-0-session-timing-attack.patch to fix the issue. As a temporary workaround, consider implementing a secure comparison for the session id in the backing store to minimize the risk of exploitation.

Exploit

Correção

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16782
GHSA-HRQR-HXPP-CHR3
MGASA-2020-0252
OPENSUSE-SU-2020:0214-1
OPENSUSE-SU-2020_0214-1
OPENSUSE-SU-2024:11312-1
OPENSUSE-SU-2024:11315-1
OPENSUSE-SU-2024:11317-1
OPENSUSE-SU-2024:11318-1
OPENSUSE-SU-2024:11320-1
OPENSUSE-SU-2024:11322-1
OPENSUSE-SU-2024:11324-1
OPENSUSE-SU-2024:11326-1
OPENSUSE-SU-2024:11328-1
OPENSUSE-SU-2024:11330-1
OPENSUSE-SU-2024:11344-1
OPENSUSE-SU-2024:11346-1
OPENSUSE-SU-2024:11347-1
OPENSUSE-SU-2024:11350-1
OPENSUSE-SU-2024:11821-1
OPENSUSE-SU-2024:12119-1
OPENSUSE-SU-2024:12397-1
OPENSUSE-SU-2024:12974-1
OPENSUSE-SU-2024:13167-1
OPENSUSE-SU-2024:13726-1
OPENSUSE-SU-2024:13727-1
OPENSUSE-SU-2025:14811-1
OPENSUSE-SU-2025:14875-1
OPENSUSE-SU-2026:10286-1
OPENSUSE-SU-2026:10358-1
RHSA-2020:2480
RHSA-2020:4366
RHSA-2021:1313
SUSE-SU-2020:0359-1
SUSE-SU-2020:2678-1
SUSE-SU-2021:1162-1
USN-5253-1

Produtos afetados

Linuxmint
Rack
Suse
Ubuntu