CVE Database
/

CVE-2007-6077

Back to search

CVE-2007-6077

Published: Nov 21, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2007-4238
vdb-entry
x_refsource_VUPEN
TA07-352A
third-party-advisory
x_refsource_CERT
28136
third-party-advisory
x_refsource_SECUNIA
27781
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2007-12-17
vendor-advisory
x_refsource_APPLE
26598
vdb-entry
x_refsource_BID
ADV-2007-4009
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now