CVE-2013-7222
02.01.2014, 14:59
config/initializers/secret_token.rb in Fat Free CRM before 0.12.1 has a fixed FatFreeCRM::Application.config.secret_token value, which makes it easier for remote attackers to spoof signed cookies by referring to the key in the source code.Enginsight
Vendor | Product | Version |
---|---|---|
fatfreecrm | fat_free_crm | 𝑥 ≤ 0.12.0 |
fatfreecrm | fat_free_crm | 0.9.6 |
fatfreecrm | fat_free_crm | 0.9.7 |
fatfreecrm | fat_free_crm | 0.9.8 |
fatfreecrm | fat_free_crm | 0.9.9 |
fatfreecrm | fat_free_crm | 0.9.10 |
fatfreecrm | fat_free_crm | 0.10.1 |
fatfreecrm | fat_free_crm | 0.11.0 |
fatfreecrm | fat_free_crm | 0.11.1 |
fatfreecrm | fat_free_crm | 0.11.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References