CVE-2020-8184

Modified
Published: 19 Jun 2020, 00:00
Last modified:04 Aug 2024, 09:56

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.81% LOW
1% probability -0.26%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

19 Jun 2020, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 09:56
Last Modified
Vulnerability information updated

Description

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 0.81% Percentile: 75%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

  • CWE-784Reliance on Cookies without Validation and Integrity Checking in a Security Decision

    The product uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure that the cookie is valid for the associated user.

Affected Systems

  • canonicalubuntu_linux

    18.04

  • debiandebian_linux

    9.0 | 10.0

  • rack_projectrack

    < 2.1.4 | ≥ 2.2.0, < 2.2.3

References (5)