Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3fhf-6939-qg8p

Опубликовано: 13 авг. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

rest-client Gem Vulnerable to Session Fixation

REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

Пакеты

Наименование

rest-client

rubygems
Затронутые версииВерсия исправления

>= 1.6.1.a, < 1.8.0

1.8.0

EPSS

Процентиль: 88%
0.03723
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

redhat
почти 11 лет назад

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

CVSS3: 9.8
nvd
больше 8 лет назад

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

CVSS3: 9.8
debian
больше 8 лет назад

REST client for Ruby (aka rest-client) before 1.8.0 allows remote atta ...

EPSS

Процентиль: 88%
0.03723
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-384