CVE-2012-2671 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2671): The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtain sensitive cookie information, hijack web sessions, or have other unspecified impact by accessing the cache. Please punt vulnerable versions.
Vulnerable versions removed.
Thanks, Hans. Closing noglsa for ~arch only.