QID 198319

Date Published: 2021-04-08

QID 198319: Ubuntu Security Notification for Ruby-rack Vulnerabilities (USN-4561-2)

USN-4561-1 fixed vulnerabilities in Rack. This update provides the corresponding update for Ubuntu 16.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10.

Original advisory details:

It was discovered that Rack incorrectly handled certain paths.

It was discovered that Rack incorrectly validated cookies.

An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-8161)

An attacker could possibly use this issue to forge a secure cookie. (CVE-2020-8184)

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu advisory USN-4561-2 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198319

    Software Advisories
    Advisory ID Software Component Link
    USN-4561-2 16.04 (Xenial) on src ruby-rack URL Logo launchpad.net/ubuntu/+source/ruby-rack/1.6.4-3ubuntu0.2
    USN-4561-2 20.04 (focal) on src ruby-rack URL Logo launchpad.net/ubuntu/+source/ruby-rack/2.0.7-2ubuntu0.1
    USN-4561-2 20.10 (groovy) on src ruby-rack URL Logo launchpad.net/ubuntu/+source/ruby-rack/2.1.1-5ubuntu0.1