Security update for rubygem-rack
This update for rubygem-rack to version 1.6.13 fixes the following issues: - CVE-2020-8184: Fixed an issue where percent-encoded cookies could have been used to overwrite existing prefixed cookie names (bsc#1173351). - CVE-2020-8161: Fixed a directory traversal (bsc#1172037). - CVE-2019-16782: Fixed an information leak / session hijack vulnerability (bsc#1159548).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for rubygem-rack to version 1.6.13 fixes the following issues: - CVE-2020-8184: Fixed an issue where percent-encoded cookies could have been used to overwrite existing prefixed cookie names (bsc#1173351). - CVE-2020-8161: Fixed a directory traversal (bsc#1172037). - CVE-2019-16782: Fixed an information leak / session hijack vulnerability (bsc#1159548).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1159548
- https://bugzilla.suse.com/1172037
- https://bugzilla.suse.com/1173351
- https://www.suse.com/security/cve/CVE-2019-16782
- https://www.suse.com/security/cve/CVE-2020-8161
- https://www.suse.com/security/cve/CVE-2020-8184
- https://www.suse.com/support/update/announcement/2020/suse-su-20202678-1/