PT-2004-1834 · Ruby · Cgi::Session
Published
2004-08-19
·
Updated
2017-10-11
·
CVE-2004-0755
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CGI::Session versions prior to 1.8.1
Description
The issue allows local users to steal session information and hijack sessions due to insecure file permissions created by the FileStore capability in CGI::Session for Ruby.
Recommendations
For versions prior to 1.8.1, update to version 1.8.1 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cgi::Session