Moderate severity vulnerability that affects rails
Published: October 24, 2017
SECURITY IDENTIFIERS
- CVE: CVE-2007-5380 (NVD)
- GHSA: GHSA-jwhv-rgqc-fqj5
- Vendor Advisory: http://weblog.rubyonrails.org/2007/10/5/rails-1-2-4-maintenance-release
GEM
FRAMEWORK
SEVERITY
CVSS v2.0: 6.8 (Medium)
PATCHED VERSIONS
>= 1.2.4
DESCRIPTION
Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions."
