Описание
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.
Отчет
With the release of Satellite 6.9 available, this bug is being closed as wontfix as all parts of our Ruby stack are running under the SCL now with rest-client.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenStack Foreman | ruby193-rubygem-rest-client | Will not fix | ||
| OpenStack Foreman | rubygem-rest-client | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer | ruby193-rubygem-rest-client | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer | rubygem-rest-client | Will not fix | ||
| Red Hat Enterprise MRG 2 | rubygem-rest-client | Will not fix | ||
| Red Hat OpenShift Enterprise 2 | ruby193-rubygem-rest-client | Will not fix | ||
| Red Hat OpenStack Platform 4 | ruby193-rubygem-rest-client | Will not fix | ||
| Red Hat OpenStack Platform 4 | rubygem-rest-client | Will not fix | ||
| Red Hat Satellite 6 | rubygem-rest-client | Will not fix | ||
| Red Hat Subscription Asset Manager | ruby193-rubygem-rest-client | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.
REST client for Ruby (aka rest-client) before 1.8.0 allows remote atta ...
EPSS
4.3 Medium
CVSS2