-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from Rack-Cache's failure to remove sensitive headers before storing responses. The critical fix (in commit 2e3a64d) added a 'strip_ignore_headers' call in the store method to remove headers like Set-Cookie. In vulnerable versions <1.2, this stripping mechanism was absent, making the store function directly responsible for persisting sensitive headers. The CVE description and patch analysis confirm this was the primary point of failure.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| rack-cache | rubygems | >= 0.3.0, < 1.2 | 1.2 |
Ongoing coverage of React2Shell