The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/MiniProfiler/rack-mini-profiler/blob/v0.10.1/CHANGELOG.md | third party advisory release notes |
http://www.openwall.com/lists/oss-security/2016/06/10/2 | mailing list third party advisory patch |
https://github.com/MiniProfiler/rack-mini-profiler/commit/4273771d65f1a7411e3ef5843329308d0e2d257c | third party advisory patch |