Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-3424

Опубликовано: 08 авг. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method. There is a DoS vulnerability in Action Pack digest authentication handling in Rails.

РелизСтатусПримечание
artful

not-affected

contains no code
bionic

not-affected

contains no code
cosmic

not-affected

contains no code
devel

not-affected

contains no code
disco

not-affected

contains no code
esm-apps/bionic

not-affected

contains no code
esm-apps/xenial

not-affected

contains no code
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [contains no code]]
hardy

not-affected

lucid

not-affected

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

esm-infra-legacy/trusty

DNE

hardy

DNE

lucid

DNE

natty

DNE

oneiric

not-affected

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
hardy

DNE

lucid

DNE

natty

DNE

oneiric

DNE

Показывать по

Ссылки на источники

EPSS

Процентиль: 76%
0.00981
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 13 лет назад

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.

nvd
больше 13 лет назад

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.

debian
больше 13 лет назад

The decode_credentials method in actionpack/lib/action_controller/meta ...

github
больше 8 лет назад

actionpack Improper Authentication vulnerability

EPSS

Процентиль: 76%
0.00981
Низкий

5 Medium

CVSS2

Уязвимость CVE-2012-3424