Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-1820

Опубликовано: 09 авг. 2017
Источник: debian

Описание

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-rest-clientfixed1.6.7-6package
ruby-rest-clientno-dsawheezypackage
librestclient-rubyremovedpackage
librestclient-rubynot-affectedwheezypackage
librestclient-rubynot-affectedsqueezepackage

Примечания

  • https://github.com/rest-client/rest-client/issues/369

  • Patch: https://github.com/rest-client/rest-client/pull/365.patch (will need new dependency to ruby-http-cookie)

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

redhat
почти 11 лет назад

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

CVSS3: 9.8
nvd
больше 8 лет назад

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

CVSS3: 9.8
github
больше 7 лет назад

rest-client Gem Vulnerable to Session Fixation