CVE-2016-4442

The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:miniprofiler:rack-mini-profiler:*:*:*:*:*:ruby:*:*

History

No history.

Information

Published : 2017-05-02 14:59

Updated : 2024-02-04 19:11


NVD link : CVE-2016-4442

Mitre link : CVE-2016-4442

CVE.ORG link : CVE-2016-4442


JSON object : View

Products Affected

miniprofiler

  • rack-mini-profiler
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor