PT-2012-4701 · Ruby · Ruby On Rails

Charlie Somerville

·

Published

2012-08-08

·

Updated

2019-08-08

·

CVE-2012-3424

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions 3.0.0 through 3.0.15 Ruby on Rails versions 3.1.0 through 3.1.6 Ruby on Rails versions 3.2.0 through 3.2.6
Description The issue allows remote attackers to cause a denial of service by leveraging access to an application that uses a with http digest helper method. This is demonstrated by the authenticate or request with http digest method, which is affected by the decode credentials method converting Digest Authentication strings to symbols.
Recommendations For Ruby on Rails versions 3.0.0 through 3.0.15, update to version 3.0.16 or later. For Ruby on Rails versions 3.1.0 through 3.1.6, update to version 3.1.7 or later. For Ruby on Rails versions 3.2.0 through 3.2.6, update to version 3.2.7 or later.

Fix

DoS

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3424
GHSA-92W9-2PQW-RHJJ
RHSA-2013:0582

Affected Products

Ruby On Rails