Ruby on Rails Session Fixation Vulnerability
BID:26598
Info
Ruby on Rails Session Fixation Vulnerability
| Bugtraq ID: | 26598 |
| Class: | Design Error |
| CVE: |
CVE-2007-6077 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2007 12:00AM |
| Updated: | Dec 21 2009 08:43AM |
| Credit: | sameer discovered this vulnerability. <br> |
| Vulnerable: |
Ruby on Rails Ruby on Rails 1.2.5 Gentoo Linux Apple Mac OS X Server 10.5.1 Apple Mac OS X 10.5.1 |
| Not Vulnerable: |
Ruby on Rails Ruby on Rails 1.2.6 |
Discussion
Ruby on Rails Session Fixation Vulnerability
Ruby on Rails is prone to a session-fixation vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
This issue affects versions prior to Ruby on Rails 1.2.6.
Ruby on Rails is prone to a session-fixation vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
This issue affects versions prior to Ruby on Rails 1.2.6.
Exploit / POC
Ruby on Rails Session Fixation Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Ruby on Rails Session Fixation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ruby on Rails Ruby on Rails 1.2.5
Apple Mac OS X Server 10.5.1
Apple Mac OS X 10.5.1
Solution:
Updates are available. Please see the references for more information.
Ruby on Rails Ruby on Rails 1.2.5
-
Ruby on Rails rails-1.2.6.tgz
http://rubyforge.org/frs/download.php/28338/rails-1.2.6.tgz
Apple Mac OS X Server 10.5.1
-
Apple Security Update 2007-009 (10.5.1)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16527&cat= 1&platform=osx&method=sa/SecUpd2007-009.dmg
Apple Mac OS X 10.5.1
-
Apple Security Update 2007-009 (10.5.1)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16527&cat= 1&platform=osx&method=sa/SecUpd2007-009.dmg
References
Ruby on Rails Session Fixation Vulnerability
References:
References:
- Ruby on Rails Homepage (Ruby on Rails)
- Ticket #10048 - Session fixation (cookie_only) functionality is broken (sameer)