Re: [CVE-2019-16782] Possible Information Leak / Session Hijack Vulnerability in Rack

Related Vulnerabilities: CVE-2019-16782  
                On Thu, 9 Apr 2020, Brian May wrote:

Not real-world as the number of installations is maybe 6 now, but
the one I wrote removes leading duplicates from index records (replacing
with a dup count).  I believe that timing the lookups could disclose
bytes as described.  It's super efficient, though.  :-)