Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92w9-2pqw-rhjj

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

actionpack Improper Authentication vulnerability

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.

Пакеты

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 3.0.0.beta, < 3.0.16

3.0.16

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 3.1.0, < 3.1.7

3.1.7

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 3.2.0, < 3.2.7

3.2.7

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

< 2.3.5

2.3.5

EPSS

Процентиль: 76%
0.00981
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 13 лет назад

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method. There is a DoS vulnerability in Action Pack digest authentication handling in Rails.

redhat
больше 13 лет назад

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.

nvd
больше 13 лет назад

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.

debian
больше 13 лет назад

The decode_credentials method in actionpack/lib/action_controller/meta ...

EPSS

Процентиль: 76%
0.00981
Низкий

Дефекты

CWE-287