Количество 11
Количество 11
CVE-2015-7576
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.
CVE-2015-7576
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.
CVE-2015-7576
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.
CVE-2015-7576
The http_basic_authenticate_with method in actionpack/lib/action_contr ...
SUSE-SU-2016:0968-1
Security update for rubygem-activesupport-3_2
SUSE-SU-2016:0623-1
Security update for rubygem-activesupport-3_2
GHSA-p692-7mm3-3fxg
actionpack is vulnerable to remote bypass authentication
BDU:2016-00815
Уязвимость программной платформы Ruby on Rails, позволяющая нарушителю обойти процедуру аутентификации
SUSE-SU-2016:0618-1
Security update for rubygem-actionpack-3_2
openSUSE-SU-2016:0372-1
Security update for rubygem-actionpack-4_2, rubygem-actionview-4_2, rubygem-activemodel-4_2, rubygem-activerecord-4_2, rubygem-activesupport-4_2
SUSE-SU-2016:1146-1
Security update for portus
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2015-7576 The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences. | CVSS3: 3.7 | 2% Низкий | почти 10 лет назад | |
CVE-2015-7576 The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences. | CVSS2: 4.3 | 2% Низкий | около 10 лет назад | |
CVE-2015-7576 The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences. | CVSS3: 3.7 | 2% Низкий | почти 10 лет назад | |
CVE-2015-7576 The http_basic_authenticate_with method in actionpack/lib/action_contr ... | CVSS3: 3.7 | 2% Низкий | почти 10 лет назад | |
SUSE-SU-2016:0968-1 Security update for rubygem-activesupport-3_2 | 2% Низкий | почти 10 лет назад | ||
SUSE-SU-2016:0623-1 Security update for rubygem-activesupport-3_2 | 2% Низкий | почти 10 лет назад | ||
GHSA-p692-7mm3-3fxg actionpack is vulnerable to remote bypass authentication | CVSS3: 3.7 | 2% Низкий | больше 8 лет назад | |
BDU:2016-00815 Уязвимость программной платформы Ruby on Rails, позволяющая нарушителю обойти процедуру аутентификации | CVSS2: 4.3 | 2% Низкий | почти 10 лет назад | |
SUSE-SU-2016:0618-1 Security update for rubygem-actionpack-3_2 | почти 10 лет назад | |||
openSUSE-SU-2016:0372-1 Security update for rubygem-actionpack-4_2, rubygem-actionview-4_2, rubygem-activemodel-4_2, rubygem-activerecord-4_2, rubygem-activesupport-4_2 | около 10 лет назад | |||
SUSE-SU-2016:1146-1 Security update for portus | почти 10 лет назад |
Уязвимостей на страницу