CVE-2025-46336 PUBLISHED CVSS 4.199999809265137 MEDIUM

Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. This issue has been patched in version 2.1.1.

EPSS 0.12% · 30.1th percentile

Risk Scores

CVSS v3.1
4.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.12%
30.1th percentile

Affected Products

VendorProductVersions
rackrack-session>= 2.0.0, < 2.1.1
RubyGemsrack-session2.0.0

Timeline

References

Open in Interactive Console →