USN-4561-2
Dashboard / Vulnerabilities / USN-4561-2
USN-4561-2
Summary: ruby-rack vulnerabilities
Details: USN-4561-1 fixed vulnerabilities in Rack. This update provides the corresponding update for Ubuntu 16.04 LTS, Ubuntu 20.04 LTS and Ubuntu 20.10. Original advisory details: It was discovered that Rack incorrectly handled certain paths. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-8161) It was discovered that Rack incorrectly validated cookies. An attacker could possibly use this issue to forge a secure cookie. (CVE-2020-8184)
References: https://ubuntu.com/security/notices/USN-4561-2, https://ubuntu.com/security/CVE-2020-8161, https://ubuntu.com/security/CVE-2020-8184
Affected packages
Package
Name: ruby-rack
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
