Количество 2
Количество 2
CVE-2008-7311
The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file.
GHSA-g466-57gh-cqfw
Spree uses a hardcoded hash value
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2008-7311 The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file. | CVSS2: 5 | 0% Низкий | почти 14 лет назад | |
GHSA-g466-57gh-cqfw Spree uses a hardcoded hash value | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу