← לוח פגיעויות

CVE-2019-16779

בינונית 5.9

תיאור (מקור, אנגלית)

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.

מדדים

CVSS 3.1
5.9 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
1% (אחוזון 100) נכון ל-4/8/2026
CWE
CWE-664, CWE-362

מוצרים מושפעים

excon_project: excon; opensuse: backports sle; opensuse: leap; debian: debian linux

קישורים