CVE-2018-1000119
rack-protection: Timing attack in authenticity_token.rb
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0.
Sinatra rack-protection, en versiones 1.5.4, 2.0.0.rc3 y anteriores, contiene una vulnerabilidad de ataque de sincronización en la comprobación de token CSRF que puede resultar en que las firmas queden expuestas. Este ataque parece ser explotable mediante conectividad de red en la aplicación Ruby. La vulnerabilidad parece haber sido solucionada en las versiones 1.5.5 y 2.0.0.
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. Issues addressed include a bypass vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-07 CVE Reserved
- 2018-03-07 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-203: Observable Discrepancy
- CWE-385: Covert Timing Channel
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/sinatra/rack-protection/pull/98 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/sinatra/sinatra/commit/8aa6c42ef724f93ae309fb7c5668e19ad547eceb#commitcomment-27964109 | 2020-08-24 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:1060 | 2020-08-24 | |
https://www.debian.org/security/2018/dsa-4247 | 2020-08-24 | |
https://access.redhat.com/security/cve/CVE-2018-1000119 | 2021-04-21 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1534027 | 2021-04-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sinatrarb Search vendor "Sinatrarb" | Rack-protection Search vendor "Sinatrarb" for product "Rack-protection" | < 1.5.5 Search vendor "Sinatrarb" for product "Rack-protection" and version " < 1.5.5" | - |
Affected
| ||||||
Sinatrarb Search vendor "Sinatrarb" | Rack-protection Search vendor "Sinatrarb" for product "Rack-protection" | 2.0.0 Search vendor "Sinatrarb" for product "Rack-protection" and version "2.0.0" | rc1 |
Affected
| ||||||
Sinatrarb Search vendor "Sinatrarb" | Rack-protection Search vendor "Sinatrarb" for product "Rack-protection" | 2.0.0 Search vendor "Sinatrarb" for product "Rack-protection" and version "2.0.0" | rc2 |
Affected
| ||||||
Sinatrarb Search vendor "Sinatrarb" | Rack-protection Search vendor "Sinatrarb" for product "Rack-protection" | 2.0.0 Search vendor "Sinatrarb" for product "Rack-protection" and version "2.0.0" | rc3 |
Affected
|