CVE-2015-1820
09.08.2017, 18:29
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.Enginsight
| Vendor | Product | Version |
|---|---|---|
| rest-client_project | rest-client | 𝑥 ≤ 1.7.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| librestclient-ruby |
| ||||||||||||||||||||||||||
| ruby-rest-client |
|
Common Weakness Enumeration
References