Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. This issue has been patched in version 2.1.1.
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 08 May 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. This issue has been patched in version 2.1.1. | |
Title | Rack session gets restored after deletion | |
Weaknesses | CWE-362 CWE-367 CWE-613 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-08T19:26:01.638Z
Updated: 2025-05-08T20:18:38.555Z
Reserved: 2025-04-22T22:41:54.911Z
Link: CVE-2025-46336

Updated: 2025-05-08T20:18:31.018Z

Status : Received
Published: 2025-05-08T20:15:30.670
Modified: 2025-05-08T20:15:30.670
Link: CVE-2025-46336

No data.