Sha256: 917c7442c3a90624ae9404cde8cf91c2c0d459e1e8d43bd0a29a887abc56213b
Contents?: true
Size: 538 Bytes
Versions: 1
Compression:
Stored size: 538 Bytes
Contents
--- gem: fat_free_crm osvdb: 101445 cve: 2013-7222 url: https://nvd.nist.gov/vuln/detail/CVE-2013-7222 title: Fat Free CRM Gem for Ruby lack of support for cycling the Rails session secret date: 2013-12-24 description: | Fat Free CRM contains a flaw that is due to the application defining a static security session token in config/initialiers/secret_token.rb. If a remote attacker has explicit knowledge of this token, they can potentially execute arbitrary code. cvss_v2: 5.0 patched_versions: - ">= 0.13.0" - "~> 0.12.1"
Version data entries
1 entries across 1 versions & 1 rubygems
Version | Path |
---|---|
bundler-audit-0.7.0.1 | data/ruby-advisory-db/gems/fat_free_crm/CVE-2013-7222.yml |