Vulnerabilities
Vulnerable Software
Rack Project:  >> Rack  >> 2.0.9.2  Security Vulnerabilities
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.
CVSS Score
8.6
EPSS Score
0.004
Published
2020-07-02
A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.
CVSS Score
7.5
EPSS Score
0.008
Published
2020-06-19


Contact Us

Shodan ® - All rights reserved