Race condition in Excon - CVE-2019-16779
Published: February 10, 2020 / Updated: February 10, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information on the target system.
The vulnerability exists due to a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. A remote attacker can exploit the race and gain unauthorized access to sensitive information on the system.
Affected software
Gitlab Community Edition
SUSE Linux
Opensuse
openEuler
rubygem-excon
rubygem-excon-help
How to mitigate CVE-2019-16779
Gitlab Community Edition - addressed in versions 12.5.9, 12.6.6, 12.7.4
rubygem-excon - update to 0.62.0-3
rubygem-excon-help - update to 0.62.0-3