Sha256: 7c7f3a1b7a79a3a43941d2629878cdb7cd86b03561c99d084aa06ddd90b19216

Contents?: true

Size: 526 Bytes

Versions: 5

Compression:

Stored size: 526 Bytes

Contents

---
gem: fat_free_crm
osvdb: 101445
cve: 2013-7222
url: http://osvdb.org/show/osvdb/101445
title: Fat Free CRM Gem for Ruby lack of support for cycling the Rails
  session secret
date: 2013-12-24
description: |
  Fat Free CRM contains a flaw that is due to the application defining a static
  security session token in config/initialiers/secret_token.rb. If a remote
  attacker has explicit knowledge of this token, they can potentially execute
  arbitrary code.
cvss_v2: 5.0
patched_versions:
  - ">= 0.13.0"
  - "~> 0.12.1"

Version data entries

5 entries across 5 versions & 2 rubygems

Version Path
bundler-budit-0.6.2 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101445.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101445.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101445.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101445.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101445.yml