CVE-2018-16471 describes a possible Cross-Site Scripting (XSS) vulnerability in Rack versions prior to 2.0.6 and 1.6.11, affecting applications that do not properly escape the return value of the Rack::Request scheme method. This medium-severity vulnerability (CVSS 6.1) can be triggered by carefully crafted requests, potentially leading to information disclosure or limited integrity impact if applications bypass or do not use standard escaping mechanisms. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, with only one minor media mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.6.0, < 1.6.11CPE matchmatch criteria | cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.0.6CPE matchmatch criteria | cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.