rubygem-rack: Timing attack in cookie sessions
Published Feb 8, 2013
5.1
MEDIUMCVSS 2.0
EPSS 5.38%
Description
Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.
Affected products
No data.
Configuration 1
- 1.5.0
- 1.5.1
Configuration 2
- 1.4.0
- 1.4.1
- 1.4.2
- 1.4.3
- 1.4.4
Configuration 3
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.5
- 1.3.6
- 1.3.7
- 1.3.8
- 1.3.9
Configuration 4
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.6
- 1.2.7
Configuration 5
- 1.1.0
- 1.1.4
- 1.1.5
- 1.1.6
No data.
RHEL 6 Version of OpenShift Enterprise
jenkins-0:1.502-1.el6op
Fixed · RHSA-2013:0638
RHEL 6 Version of OpenShift Enterprise
openshift-origin-cartridge-jenkins-1.4-0:1.0.3-1.el6op
Fixed · RHSA-2013:0638
RHEL 6 Version of OpenShift Enterprise
ruby193-rubygem-rack-1:1.3.0-4.el6op
Fixed · RHSA-2013:0638
RHEL 6 Version of OpenShift Enterprise
ruby193-rubygem-rack-1:1.4.1-4.el6
Fixed · RHSA-2013:0638
RHEL 6 Version of OpenShift Enterprise
rubygem-rack-1:1.3.0-4.el6op
Fixed · RHSA-2013:0638
Red Hat Subscription Asset Manager 1.2
candlepin-0:0.7.24-1.el6_3
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
katello-0:1.2.1.1-1h.el6_4
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
katello-configure-0:1.2.3.1-4h.el6_4
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
rubygem-actionpack-1:3.0.10-12.el6cf
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
rubygem-activemodel-0:3.0.10-3.el6cf
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
rubygem-delayed_job-0:2.1.4-3.el6cf
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
rubygem-json-0:1.7.3-2.el6_3
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
rubygem-rack-1:1.3.0-4.el6cf
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
rubygem-rails_warden-0:0.5.5-2.el6cf
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
rubygem-rdoc-0:3.8-6.el6cf
Fixed · RHSA-2013:0686
Red Hat Subscription Asset Manager 1.2
thumbslug-0:0.0.28.1-1.el6_4
Fixed · RHSA-2013:0686
Red Hat Enterprise MRG 2
rubygem-rack
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEL 6 Version of OpenShift Enterprise | jenkins-0:1.502-1.el6op | Fixed | RHSA-2013:0638 |
| RHEL 6 Version of OpenShift Enterprise | openshift-origin-cartridge-jenkins-1.4-0:1.0.3-1.el6op | Fixed | RHSA-2013:0638 |
| RHEL 6 Version of OpenShift Enterprise | ruby193-rubygem-rack-1:1.3.0-4.el6op | Fixed | RHSA-2013:0638 |
| RHEL 6 Version of OpenShift Enterprise | ruby193-rubygem-rack-1:1.4.1-4.el6 | Fixed | RHSA-2013:0638 |
| RHEL 6 Version of OpenShift Enterprise | rubygem-rack-1:1.3.0-4.el6op | Fixed | RHSA-2013:0638 |
| Red Hat Subscription Asset Manager 1.2 | candlepin-0:0.7.24-1.el6_3 | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | katello-0:1.2.1.1-1h.el6_4 | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | katello-configure-0:1.2.3.1-4h.el6_4 | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | rubygem-actionpack-1:3.0.10-12.el6cf | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | rubygem-activemodel-0:3.0.10-3.el6cf | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | rubygem-delayed_job-0:2.1.4-3.el6cf | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | rubygem-json-0:1.7.3-2.el6_3 | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | rubygem-rack-1:1.3.0-4.el6cf | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | rubygem-rails_warden-0:0.5.5-2.el6cf | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | rubygem-rdoc-0:3.8-6.el6cf | Fixed | RHSA-2013:0686 |
| Red Hat Subscription Asset Manager 1.2 | thumbslug-0:0.0.28.1-1.el6_4 | Fixed | RHSA-2013:0686 |
| Red Hat Enterprise MRG 2 | rubygem-rack | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.38% (0.05383) | 92.42th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.28% (0.05281) | 91.49th | v5 (v2026.06.15) |
| Apr 20, 2026 | 16.07% (0.16071) | 94.80th | v4 (v2025.03.14) |
| Mar 26, 2026 | 8.63% (0.08626) | 92.38th | v4 (v2025.03.14) |
| Jul 14, 2025 | 5.28% (0.05283) | 89.55th | v4 (v2025.03.14) |
| Mar 30, 2025 | 7.96% (0.07962) | 91.26th | v4 (v2025.03.14) |
| Mar 29, 2025 | 17.63% (0.17625) | 91.91th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.96% (0.07962) | 91.45th | v4 (v2025.03.14) |
| Dec 17, 2024 | 6.63% (0.06630) | 93.72th | v3 (v2023.03.01) |
| May 15, 2023 | 8.35% (0.08350) | 93.42th | v3 (v2023.03.01) |
| Mar 7, 2023 | 9.48% (0.09477) | 93.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 9.92% (0.09915) | 94.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 9.92% (0.09915) | 94.04th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.92% (0.09915) | 87.53th | v2 (v2022.01.01) |
No CWE recorded.
References (27)
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html vendor-advisoryx_refsource_SUSE
- http://rack.github.com/ x_refsource_CONFIRMVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0686.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/52033 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/52134 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/52774 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2013/dsa-2783 vendor-advisoryx_refsource_DEBIAN
- http://www.osvdb.org/89939 vdb-entryx_refsource_OSVDB
- https://access.redhat.com/security/cve/CVE-2013-0263 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=909071 x_refsource_MISCIssue Tracking
- https://gist.github.com/codahale/f9f3781f7b54985bee94 x_refsource_MISC
- https://github.com/advisories/GHSA-xc85-32mf-xpv8 Advisory
- https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07 x_refsource_CONFIRM
- https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11 x_refsource_CONFIRM
- https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J x_refsource_CONFIRM
- https://groups.google.com/forum/#!msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ
- https://groups.google.com/forum/#!msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ
- https://groups.google.com/forum/#!msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ
- https://groups.google.com/forum/#!msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ
- https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ x_refsource_CONFIRM
- https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ x_refsource_CONFIRM
- https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ x_refsource_CONFIRM
- https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2013-0263
- https://puppet.com/security/cve/cve-2013-0263 x_refsource_CONFIRM
- https://twitter.com/coda/statuses/299732877745197056 x_refsource_MISC
- https://www.cve.org/CVERecord?id=CVE-2013-0263
Change history (0)
No recorded changes yet.