39193 : Ruby on Rails cgi_process.rb Cookie Related Session Fixation
Printer | http://osvdb.org/39193 | Email This | Edit Vulnerability

Views This Week

3

Views All Time

113

Info

Last Modified

8 months ago

Percent Complete

90%

Disclosure

Oct 12, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Ruby on Rails contains a flaw that may allow a malicious user to hijack the session of another via session fixation.

Classification

Location: Remote/Network Access Required
Attack Type: Hijacking
Impact: Loss of Confidentiality
Solution: Upgrade
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Upgrade to rails 1.2.6 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Ruby on Rails
Watch-list
Ruby on Rails
Watch-list
1.2.5

References

Tools & Filters

Nessus

28333 28348

Credit

Unknown or Incomplete

Blogs

2007/11/25 18:48:58 | Riding Rails: Ruby on Rails 1.2.6

from: CMS Report's Front Page News | CMS Report

Riding Rails: Ruby on Rails 1.2.6 Submitted by CMS Report on November 25, 2007 - 12:48pm. "The rails core team has released ruby on rails 1.2.6 to address a bug in the fix for session fixation attacks (CVE-2007-5380). The CVE Identifier for this new issue is CVE-2007-6077." Complete Story »

2007/11/25 10:58:51 | Rails 1.2.6 security update

from: Ruby on Rails Security Project — Exploring the Security of Rails and friends.

The rails core team has released ruby on rails 1.2.6 to address a bug in the fix for session fixation attacks (CVE-2007-5380). The CVE Identifier for this new issue is CVE-2007-6077. You should upgrade to this new release if you do not take specific session-fixation counter measures in your application. 1.2.6 also

2007/11/25 08:16:56 | Ruby on Rails 1.2.6: Security and Maintenance Release

from: Nixforce.com a site dedicated to opensource products, like Linux, Debian, php, mysql and more

Ruby on Rails 1.2.6: Security and Maintenance Release The rails core team has released ruby on rails 1.2.6 to address a bug in the fix for session fixation attacks (CVE-2007-5380). The CVE Identifier for this new issue is CVE-2007-6077. You should upgrade to this new release if you do not take

2007/11/24 22:20:13 | Permanent link to Ruby on Rails 1.2.6

from: Pardel’s Blog

Ruby on Rails 1.2.6 November 24, 2007 at 11:19 pm · Filed under Ruby on Rails The rails core team has released ruby on rails 1.2.6 to address a bug in the fix for session fixation attacks(CVE-2007-5380). The CVE Identifier for this new issue is CVE-2007-6077.You should upgrade to this new release if you do not take specific

2007/11/24 22:19:55 | Ruby on Rails 1.2.6: Security and Maintenance Release

from: Riding Rails

The rails core team has released ruby on rails 1.2.6 to address a bug in the fix for session fixation attacks (CVE-2007-5380). The CVE Identifier for this new issue is CVE-2007-6077. You should upgrade to this new release if you do not take specific session-fixation counter measures in your application. 1.2.6 also fixes

2007/11/26 01:35:46 | CVE-2007-6077 (Ruby on Rails)

from: VulnAware.com

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes :cookie_only to only be applied to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks

Comments

d2d - 2007/12/18 19:48:10

This was the result of an 'incomplete' fix for a previous vulnerability of the same nature.


DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use