In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade rack-session to version 2.1.2 or higher.
rack-session is a session implementation for Rack.
Affected versions of this package are vulnerable to Not Failing Securely ('Failing Open') in the Rack::Session::Cookie() function when it is configured with the secrets: option. An attacker can gain unauthorized access or escalate privileges by supplying a crafted session cookie that if decryption fails is accepted as valid.