
Cloud Vulnerability DB
A community-led vulnerabilities database
The activerecord-session_store (aka Active Record Session Store) component through version 1.1.3 for Ruby on Rails contained a timing attack vulnerability. The vulnerability was discovered when the component did not use a constant-time approach when delivering information about whether a guessed session ID is valid. This allowed remote attackers to leverage timing discrepancies to achieve a correct guess in a relatively short amount of time. This vulnerability is related to CVE-2019-16782 (NVD).
The vulnerability was assigned a CVSS v3.1 Base Score of 5.3 (Medium) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The issue stems from the session store's implementation not using constant-time operations when verifying session IDs, making it susceptible to timing attacks. The vulnerability affects the component's session ID validation mechanism (NVD).
The vulnerability allows remote attackers to potentially hijack user sessions by exploiting timing differences in session ID validation. This could lead to unauthorized access to user accounts and sensitive information protected by session authentication (Red Hat Portal).
The vulnerability can be exploited remotely without requiring authentication or user interaction. An attacker can leverage timing discrepancies in the session ID validation process to potentially guess valid session IDs through systematic attempts (NVD).
The vulnerability was fixed in version 2.0.0 of the activerecord-session_store component. The fix implements a secure variant of the session store using ActionDispatch::Session::AbstractSecureStore, preventing timing attacks. For users unable to upgrade immediately, a temporary workaround was available by using the rails-lts fork with the secure-session-store branch (GitHub PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."