Логотип exploitDog
bind:CVE-2015-7576
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-7576

Количество 11

Количество 11

ubuntu логотип

CVE-2015-7576

почти 10 лет назад

The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2015-7576

около 10 лет назад

The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-7576

почти 10 лет назад

The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2015-7576

почти 10 лет назад

The http_basic_authenticate_with method in actionpack/lib/action_contr ...

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:0968-1

почти 10 лет назад

Security update for rubygem-activesupport-3_2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:0623-1

почти 10 лет назад

Security update for rubygem-activesupport-3_2

EPSS: Низкий
github логотип

GHSA-p692-7mm3-3fxg

больше 8 лет назад

actionpack is vulnerable to remote bypass authentication

CVSS3: 3.7
EPSS: Низкий
fstec логотип

BDU:2016-00815

почти 10 лет назад

Уязвимость программной платформы Ruby on Rails, позволяющая нарушителю обойти процедуру аутентификации

CVSS2: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:0618-1

почти 10 лет назад

Security update for rubygem-actionpack-3_2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:0372-1

около 10 лет назад

Security update for rubygem-actionpack-4_2, rubygem-actionview-4_2, rubygem-activemodel-4_2, rubygem-activerecord-4_2, rubygem-activesupport-4_2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:1146-1

почти 10 лет назад

Security update for portus

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-7576

The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

CVSS3: 3.7
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2015-7576

The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

CVSS2: 4.3
2%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-7576

The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

CVSS3: 3.7
2%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-7576

The http_basic_authenticate_with method in actionpack/lib/action_contr ...

CVSS3: 3.7
2%
Низкий
почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:0968-1

Security update for rubygem-activesupport-3_2

2%
Низкий
почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:0623-1

Security update for rubygem-activesupport-3_2

2%
Низкий
почти 10 лет назад
github логотип
GHSA-p692-7mm3-3fxg

actionpack is vulnerable to remote bypass authentication

CVSS3: 3.7
2%
Низкий
больше 8 лет назад
fstec логотип
BDU:2016-00815

Уязвимость программной платформы Ruby on Rails, позволяющая нарушителю обойти процедуру аутентификации

CVSS2: 4.3
2%
Низкий
почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:0618-1

Security update for rubygem-actionpack-3_2

почти 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:0372-1

Security update for rubygem-actionpack-4_2, rubygem-actionview-4_2, rubygem-activemodel-4_2, rubygem-activerecord-4_2, rubygem-activesupport-4_2

около 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:1146-1

Security update for portus

почти 10 лет назад

Уязвимостей на страницу