Sha256: f8165475cce590dbac8883388c28cda6729e91bc56098e9b0262fcf4a91c20a0

Contents?: true

Size: 835 Bytes

Versions: 1

Compression:

Stored size: 835 Bytes

Contents

---
gem: excon
cve: 2019-16779
ghsa: q58g-455p-8vw9
url: https://github.com/excon/excon/security/advisories/GHSA-q58g-455p-8vw9
date: 2019-12-16
title: Race condition when using persistent connections
description: |-
  There was a race condition around persistent connections, where a connection
  which is interrupted (such as by a timeout) would leave data on the socket.
  Subsequent requests would then read this data, returning content from the
  previous response. The race condition window appears to be short, and it
  would be difficult to purposefully exploit this.

  Users can workaround the problem by disabling persistent connections, though
  this may cause performance implications.

patched_versions:
  - ">= 0.71.0"

related:
  url:
   - https://github.com/excon/excon/commit/ccb57d7a422f020dc74f1de4e8fb505ab46d8a29

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/excon/CVE-2019-16779.yml