Sha256: 8bb518020095a07a27a8da1318e5c5c1a63487f1ca7aeeb99060f9990b96ec4f

Contents?: true

Size: 732 Bytes

Versions: 1

Compression:

Stored size: 732 Bytes

Contents

---
gem: actionpack
framework: rails
cve: 2012-3424
osvdb: 84243
url: https://nvd.nist.gov/vuln/detail/CVE-2012-3424
title:
  Ruby on Rails actionpack/lib/action_controller/metal/http_authentication.rb
  with_http_digest Helper Method Remote DoS
date: 2012-07-26

description: |
  Ruby on Rails contains a flaw that may allow a remote denial of service.
  The issue is triggered when an error occurs in
  actionpack/lib/action_controller/metal/http_authentication.rb when the
  with_http_digest helper method is being used. This may allow a remote
  attacker to cause a loss of availability for the program.

cvss_v2: 5.0

unaffected_versions:
  - ">= 2.3.5, <= 2.3.14"

patched_versions:
  - ~> 3.0.16
  - ~> 3.1.7
  - ">= 3.2.7"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/actionpack/CVE-2012-3424.yml