RubySec

Providing security resources for the Ruby community

CVE-2015-1820 (rest-client): CVE-2015-1820 rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses

CVE-2015-1820 rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses

Published: March 24, 2015

SECURITY IDENTIFIERS

GEM

rest-client

SEVERITY

CVSS v3.x: 9.8 (Critical)

UNAFFECTED VERSIONS

<= 1.6.0

PATCHED VERSIONS

>= 1.8.0

DESCRIPTION

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.