← Vulnerability feed

Vulnerability record · CVE-2013-0263 · published 8 February 2013

CVE-2013-0263: Rack project rack vulnerability

Rack Project · Rack

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

5.1 CVSS 2.0 Medium EPSS 5.4% · top 7.6%
5.1CVSS 2.0 base score
5.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
38References
16 Jun 2026Last modified by NVD

Description

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html
http://rack.github.com/ Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0686.html
http://secunia.com/advisories/52033 Vendor Advisory
http://secunia.com/advisories/52134 Vendor Advisory
http://secunia.com/advisories/52774
http://www.debian.org/security/2013/dsa-2783
http://www.osvdb.org/89939
https://bugzilla.redhat.com/show_bug.cgi?id=909071
https://gist.github.com/codahale/f9f3781f7b54985bee94
https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07
https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11
https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J
https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ
https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ
https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ
https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ
https://puppet.com/security/cve/cve-2013-0263
https://twitter.com/coda/statuses/299732877745197056
http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html
http://rack.github.com/ Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0686.html
http://secunia.com/advisories/52033 Vendor Advisory
http://secunia.com/advisories/52134 Vendor Advisory
http://secunia.com/advisories/52774
http://www.debian.org/security/2013/dsa-2783
http://www.osvdb.org/89939
https://bugzilla.redhat.com/show_bug.cgi?id=909071
https://gist.github.com/codahale/f9f3781f7b54985bee94
https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07
https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11
https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J
https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ
https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ
https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ
https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ
https://puppet.com/security/cve/cve-2013-0263
https://twitter.com/coda/statuses/299732877745197056

Track CVE-2013-0263 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-30123Rack project rack vulnerabilityA sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and Common…EPSS 1.9%8.6CVE-2020-8161Rack project rack path traversal vulnerabilityA directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory a…EPSS 3.4%7.5CVE-2022-30122Rack project rack uncontrolled resource consumption vulnerabilityA possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.EPSS 2.2%7.5CVE-2020-8184Rack project rack improper input validation vulnerabilityA reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an…EPSS 2.9%7.5CVE-2018-16470Rack project rack uncontrolled resource consumption vulnerabilityThere is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to ente…EPSS 2.0%6.1CVE-2018-16471Rack project rack cross-site scripting vulnerabilityThere is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method…EPSS 1.9%5.0CVE-2015-3225Rack project rack vulnerabilitylib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to …EPSS 8.0%5.0CVE-2013-0183Rack project rack memory buffer overflow vulnerabilitymultipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and ou…EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2013-0263), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.