cbcvebase.
CVE-2019-16779
published 2019-12-16

CVE-2019-16779: In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would…

PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.40%
69.4th percentile
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianruby-excon< ruby-excon 0.60.0-2 (bookworm)ruby-excon 0.60.0-2 (bookworm)
exconexcon< 0.71.00.71.0
exconexcon>= 0 < 0.71.00.71.0
excon_projectexcon< 0.71.00.71.0
opensusebackports_sle
opensuseleap

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.