Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4c6-77gc-694x

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

session fixation protection mechanism in cgi_process.rb in Rails

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.

Пакеты

Наименование

rails

rubygems
Затронутые версииВерсия исправления

< 1.2.6

1.2.6

EPSS

Процентиль: 88%
0.0415
Низкий

Дефекты

CWE-362

Связанные уязвимости

ubuntu
около 18 лет назад

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.

nvd
около 18 лет назад

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.

debian
около 18 лет назад

The session fixation protection mechanism in cgi_process.rb in Rails 1 ...

EPSS

Процентиль: 88%
0.0415
Низкий

Дефекты

CWE-362