Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names
High severity
GitHub Reviewed
Published
Jun 24, 2020
to the GitHub Advisory Database
•
Updated Aug 28, 2023
Description
Published by the National Vulnerability Database
Jun 19, 2020
Reviewed
Jun 24, 2020
Published to the GitHub Advisory Database
Jun 24, 2020
Last updated
Aug 28, 2023
A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it possible for an attacker to forge a secure or host-only cookie prefix.
References