CVE-2009-3086: Infoleak
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3086?
CVE-2009-3086 is classified as a medium severity vulnerability due to the potential for information disclosure and remote code execution via crafted requests.
How do I fix CVE-2009-3086?
To fix CVE-2009-3086, upgrade Ruby on Rails to version 2.3.4 or higher.
What versions of Ruby on Rails are affected by CVE-2009-3086?
CVE-2009-3086 affects Ruby on Rails versions 2.1.0 through 2.2.2 and all 2.3.x versions prior to 2.3.4.
Can CVE-2009-3086 be exploited remotely?
Yes, CVE-2009-3086 can be exploited remotely, allowing attackers to forge message-digest signatures.
What impact does CVE-2009-3086 have on security?
The impact of CVE-2009-3086 includes the potential for unauthorized access and manipulation of secured cookie data.