RubySec

Providing security resources for the Ruby community

CVE-2015-1820 (rest-client): CVE-2015-1820 rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses

ADVISORIES

GEM

rest-client

SEVERITY

CVSS v3.x: 9.8 (Critical)

UNAFFECTED VERSIONS

  • <= 1.6.0

PATCHED VERSIONS

  • >= 1.8.0

DESCRIPTION

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.