oss-sec mailing list archives
CVE request: rack-cache caches sensitive headers (Set-Cookie)
From: Matthias Weckbecker <mweckbecker () suse de>
Date: Wed, 6 Jun 2012 11:09:19 +0200
Hi Kurt, Steve, vendors, rake-cache caches sensitive response headers such as Set-Cookie. Attackers with access to the cache could possibly obtain other user's cookies to e.g. bypass authentication. More information (including patch) available at our bugzilla: https://bugzilla.novell.com/show_bug.cgi?id=763650 Kurt, could you possibly assign a CVE for this issue, please? Thank you in advance! Matthias -- Matthias Weckbecker, Junior Security Engineer, SUSE Security Team SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany Tel: +49-911-74053-0; http://suse.com/ SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg)
Current thread:
- CVE request: rack-cache caches sensitive headers (Set-Cookie) Matthias Weckbecker (Jun 06)
- Re: CVE request: rack-cache caches sensitive headers (Set-Cookie) Jan Lieskovsky (Jun 06)
- Re: CVE request: rack-cache caches sensitive headers (Set-Cookie) Kurt Seifried (Jun 06)
- Re: CVE request: rack-cache caches sensitive headers (Set-Cookie) Jan Lieskovsky (Jun 06)