CVE-2015-1820 rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses
Published: March 24, 2015
SECURITY IDENTIFIERS
- CVE: CVE-2015-1820 (NVD)
- GHSA: GHSA-3fhf-6939-qg8p
- OSVDB: OSVDB-119878
- Vendor Advisory: https://github.com/rest-client/rest-client/issues/369
GEM
SEVERITY
CVSS v3.x: 9.8 (Critical)
UNAFFECTED VERSIONS
<= 1.6.0
PATCHED VERSIONS
>= 1.8.0
DESCRIPTION
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.
