PT-2012-4701 · Ruby · Ruby On Rails

Charlie Somerville

·

Publicado

2012-08-08

·

Atualizado

2019-08-08

·

CVE-2012-3424

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions 3.0.0 through 3.0.15 Ruby on Rails versions 3.1.0 through 3.1.6 Ruby on Rails versions 3.2.0 through 3.2.6
Description The issue allows remote attackers to cause a denial of service by leveraging access to an application that uses a with http digest helper method. This is demonstrated by the authenticate or request with http digest method, which is affected by the decode credentials method converting Digest Authentication strings to symbols.
Recommendations For Ruby on Rails versions 3.0.0 through 3.0.15, update to version 3.0.16 or later. For Ruby on Rails versions 3.1.0 through 3.1.6, update to version 3.1.7 or later. For Ruby on Rails versions 3.2.0 through 3.2.6, update to version 3.2.7 or later.

Correção

DoS

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3424
GHSA-92W9-2PQW-RHJJ
RHSA-2013:0582

Produtos afetados

Ruby On Rails