rest-client Gem Vulnerable to Session Fixation
Critical severity
GitHub Reviewed
Published
Aug 13, 2018
to the GitHub Advisory Database
•
Updated Sep 5, 2023
Description
Published to the GitHub Advisory Database
Aug 13, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 5, 2023
REST client for Ruby (aka rest-client) versions 1.6.1.a until 1.8.0 allow remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.
References