rack-protection
Protect against typical web attacks, works with all Rack apps, including Rails
Activity
- Latest release
- 11mo ago
- Total releases
- 53
- Cadence
- ~2 months
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jun 20, 2011
| Version | Released | |
|---|---|---|
4.2.1
patch
| ||
4.2.0
minor
| ||
4.0.1
patch
| ||
4.1.1
patch
| ||
4.1.0
minor
| ||
4.0.0
major
| ||
3.2.0
minor
| ||
3.1.0
minor
| ||
3.0.6
patch
| ||
2.2.4
patch
| ||
3.0.5
patch
| ||
2.2.3
patch
| ||
3.0.4
patch
| ||
3.0.3
patch
| ||
3.0.2
patch
| ||
3.0.0
major
| ||
3.0.1
patch
| ||
2.2.2
patch
| ||
2.2.1
patch
| ||
2.2.0
minor
| ||
2.1.0
minor
| ||
2.0.8
patch
| ||
2.0.8.1
patch
| ||
2.0.7
patch
| ||
2.0.6
patch
| ||
2.0.5
patch
| ||
2.0.4
patch
| ||
2.0.3
patch
| ||
2.0.2
patch
| ||
1.5.5
patch
| ||
1.5.4
patch
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.1
patch
| ||
2.0.1.rc1
pre
| ||
2.0.0
major
| ||
2.0.0.rc5
pre
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.0.rc6
pre
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.0.rc2
pre
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.0.rc1
pre
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.0.beta1
pre
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.0.0.beta2
pre
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.5.3
patch
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.5.2
patch
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.5.1
patch
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.3.2
patch
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.3.1
minor
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.3
patch
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.4
patch
1 CVE
CVE-2018-1000119
GHSA-688c-3x49-6rqj
Mar 07, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. Affected versions
0.1.0
1.0.0
1.1.2
1.1.3
1.1.4
1.2.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.5.2
+ 8 more Show less
1.5.3
1.5.4
2.0.0.beta1
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.0.rc5
2.0.0.rc6
Fixed in
1.5.5
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev |