CVE-2020-8184 – rack
Package
Manager: gem
Name: rack
Vulnerable Version: >=0 <2.1.4 || >=2.2.0 <2.2.3
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00844 pctl0.73918
Details
Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it possible for an attacker to forge a secure or host-only cookie prefix.
Metadata
Created: 2020-06-24T17:15:00Z
Modified: 2023-08-28T12:13:59Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-j6w9-fv6q-3q52/GHSA-j6w9-fv6q-3q52.json
CWE IDs: ["CWE-20", "CWE-784"]
Alternative ID: GHSA-j6w9-fv6q-3q52
Finding: F063
Auto approve: 1