Vulnerability Name: | CVE-2007-5380 (CCN-38340) | ||||||||
Assigned: | 2007-10-05 | ||||||||
Published: | 2007-10-05 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions." | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Dec 17 2007 - 15:47:29 CST Apple OS X Software Update Remote Command Execution Source: CONFIRM Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=195315 Source: MITRE Type: CNA CVE-2007-5380 Source: CCN Type: Apple Web site About Security Update 2007-009 Source: CONFIRM Type: UNKNOWN http://docs.info.apple.com/article.html?artnum=307179 Source: APPLE Type: UNKNOWN APPLE-SA-2007-12-17 Source: SECUNIA Type: UNKNOWN 27657 Source: SECUNIA Type: UNKNOWN 27965 Source: CCN Type: SA28136 Apple Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 28136 Source: GENTOO Type: UNKNOWN GLSA-200711-17 Source: CCN Type: Ruby On Rails Blog, October 05, 2007 @ 04:38 AM Rails 1.2.4: Maintenance release Source: CONFIRM Type: UNKNOWN http://weblog.rubyonrails.org/2007/10/5/rails-1-2-4-maintenance-release Source: CCN Type: GLSA-200711-17 Ruby on Rails: Multiple vulnerabilities Source: CCN Type: GLSA-200912-02 Ruby on Rails: Multiple vulnerabilities Source: SUSE Type: UNKNOWN SUSE-SR:2007:025 Source: CCN Type: OSVDB ID: 40718 Ruby on Rails URL-based Sessions Unspecified Session Fixation Source: BID Type: Patch 26096 Source: CCN Type: BID-26096 Ruby on Rails Multiple Vulnerabilities Source: CERT Type: US Government Resource TA07-352A Source: VUPEN Type: UNKNOWN ADV-2007-3508 Source: VUPEN Type: UNKNOWN ADV-2007-4238 Source: XF Type: UNKNOWN rails-web-session-hijacking(38340) Source: SUSE Type: SUSE-SR:2007:025 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |