« Back to list

CVE-2012-2671

Status: ModifiedHigh (7.5)—

The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2012-2671",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-06-17T03:41:41.437",
  "references": [
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081812.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/06/06/4",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/06/06/8",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=763650",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=824520",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/rtomayko/rack-cache/blob/master/CHANGES",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/rtomayko/rack-cache/commit/2e3a64d07daac4c757cc57620f2288e865a09b90",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/rtomayko/rack-cache/pull/52",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081812.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/06/06/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/06/06/8",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=763650",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=824520",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/rtomayko/rack-cache/blob/master/CHANGES",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/rtomayko/rack-cache/commit/2e3a64d07daac4c757cc57620f2288e865a09b90",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/rtomayko/rack-cache/pull/52",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache."
    },
    {
      "lang": "es",
      "value": "El Rack::Cache de rubygem v0.3.0 hasta la v1.1 almacena (en cache) Set-Cookie y otros encabezados sensibles, lo que permite a los atacantes obtener información confidencial de las cookies, secuestrar sesiones web, o tener un impacto no especificado mediante el acceso a la caché."
    }
  ],
  "lastModified": "2026-06-16T23:41:50.973",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rtomayko:rack-cach:0.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5923E7DD-281B-4291-88C2-87B9196A8F07"
            },
            {
              "criteria": "cpe:2.3:a:rtomayko:rack-cach:0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBA313AF-BF9A-4427-B336-7A6B25E6BBC2"
            },
            {
              "criteria": "cpe:2.3:a:rtomayko:rack-cach:0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F54DF9AA-4828-4373-BE0F-F76423AF495F"
            },
            {
              "criteria": "cpe:2.3:a:rtomayko:rack-cach:0.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83ACC7E3-8B18-472B-8B3B-8AE984DC1F5A"
            },
            {
              "criteria": "cpe:2.3:a:rtomayko:rack-cach:0.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9750927-2136-48EA-ADB8-2A7CE7310525"
            },
            {
              "criteria": "cpe:2.3:a:rtomayko:rack-cach:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58E442E4-80A1-4AB1-A1BD-C15C81C1FE4B"
            },
            {
              "criteria": "cpe:2.3:a:rtomayko:rack-cach:1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "780342DD-AFAC-440A-92E2-B7C09CD01269"
            },
            {
              "criteria": "cpe:2.3:a:rtomayko:rack-cach:1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3781271-7D47-44FC-99D5-38E2D390A131"
            },
            {
              "criteria": "cpe:2.3:a:rtomayko:rack-cach:1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6EAEF4F-E5D2-49A4-AF11-7F7EC02CCAA9"
            },
            {
              "criteria": "cpe:2.3:a:rtomayko:rack-cach:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13DC0743-0092-4011-963D-F3F273894771"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}