Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-7576

Опубликовано: 16 фев. 2016
Источник: debian
EPSS Низкий

Описание

The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:4.2.5.1-1package
railsnot-affectedwheezypackage
railsend-of-lifesqueezepackage
ruby-actionpack-3.2removedpackage
ruby-actionpack-2.3removedpackage
ruby-actionpack-2.3end-of-lifewheezypackage
ruby-activesupport-3.2removedpackage
ruby-activesupport-3.2not-affectedwheezypackage
ruby-activesupport-2.3removedpackage
ruby-activesupport-2.3end-of-lifewheezypackage

Примечания

  • https://github.com/rails/rails/commit/a6fa3960c3a149e83eb2ff057be4472a82958e3d

EPSS

Процентиль: 81%
0.01574
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
почти 10 лет назад

The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

redhat
около 10 лет назад

The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

CVSS3: 3.7
nvd
почти 10 лет назад

The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

suse-cvrf
почти 10 лет назад

Security update for rubygem-activesupport-3_2

suse-cvrf
почти 10 лет назад

Security update for rubygem-activesupport-3_2

EPSS

Процентиль: 81%
0.01574
Низкий