Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 6 Jun 2012 11:09:19 +0200
From: Matthias Weckbecker <mweckbecker@...e.de>
To: oss-security@...ts.openwall.com
Subject: CVE request: rack-cache caches sensitive headers (Set-Cookie)

Hi Kurt, Steve, vendors,

rake-cache caches sensitive response headers such as Set-Cookie. Attackers 
with access to the cache could possibly obtain other user's cookies to e.g. 
bypass authentication.

More information (including patch) available at our bugzilla:
  https://bugzilla.novell.com/show_bug.cgi?id=763650

Kurt, could you possibly assign a CVE for this issue, please? Thank you in
advance!

Matthias

-- 
Matthias Weckbecker, Junior Security Engineer, SUSE Security Team
SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany
Tel: +49-911-74053-0;  http://suse.com/
SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg) 

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.