rack-protection gem timing attack vulnerability when validating CSRF token
Published: March 07, 2018
SECURITY IDENTIFIERS
- CVE: CVE-2018-1000119 (NVD)
- GHSA: GHSA-688c-3x49-6rqj
- Vendor Advisory: https://github.com/sinatra/rack-protection/pull/98
GEM
SEVERITY
PATCHED VERSIONS
~> 1.5.5
>= 2.0.0
DESCRIPTION
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application.
