Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-1820

Опубликовано: 09 авг. 2017
Источник: debian
EPSS Низкий

Описание

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-rest-clientfixed1.6.7-6package
ruby-rest-clientno-dsawheezypackage
librestclient-rubyremovedpackage
librestclient-rubynot-affectedwheezypackage
librestclient-rubynot-affectedsqueezepackage

Примечания

  • https://github.com/rest-client/rest-client/issues/369

  • Patch: https://github.com/rest-client/rest-client/pull/365.patch (will need new dependency to ruby-http-cookie)

EPSS

Процентиль: 90%
0.04345
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

redhat
больше 11 лет назад

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

CVSS3: 9.8
nvd
около 9 лет назад

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

CVSS3: 9.8
github
около 8 лет назад

rest-client Gem Vulnerable to Session Fixation

EPSS

Процентиль: 90%
0.04345
Низкий