Skip to content

rack-mini-profiler allows remote attackers to obtain sensitive information about allocated strings and objects

Moderate severity GitHub Reviewed Published Oct 24, 2017 to the GitHub Advisory Database • Updated Jan 23, 2023

Package

bundler rack-mini-profiler (RubyGems)

Affected versions

< 0.10.1

Patched versions

0.10.1

Description

The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.

References

Published to the GitHub Advisory Database Oct 24, 2017
Reviewed Jun 16, 2020
Last updated Jan 23, 2023

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CVE ID

CVE-2016-4442

GHSA ID

GHSA-j5hj-fhc9-g24m
Checking history
See something to contribute? Suggest improvements for this vulnerability.